CWE
20
Advisory Published
Updated

CVE-2024-38483: Input Validation

First published: Wed Aug 14 2024(Updated: )

Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

Credit: security_alert@emc.com

Affected SoftwareAffected VersionHow to fix
All of
Dell Latitude 5290 2-in-1 Firmware<1.35.0
Dell Latitude 5290 2-in-1 Firmware
All of
Dell Precision 3420 Tower Firmware<2.32.0
Dell Precision 3420 Firmware
All of
Dell Precision 3620 Firmware<2.32.0
Dell Precision 3620 Tower
All of
Dell Wyse 7040 Thin Firmware<1.26.0
Dell Wyse 7040 Thin Firmware
All of
Dell Precision 7720 Firmware<1.37.0
Dell Precision 7720 Firmware
All of
Dell Precision 7520 Firmware=1.37.0
Dell Precision 7520 Firmware
All of
Dell Precision 5530 2-in-1 Firmware<1.32.8
Dell Precision 5530 2-in-1 Firmware
All of
Dell Precision 5520 Firmware<1.39.0
Dell Precision 5520 Firmware
All of
Dell Precision 3520 Firmware<1.37.0
Dell Precision 3520 Firmware
All of
Dell OptiPlex 7450 AIO Firmware<1.34.0
Dell OptiPlex 7450 AIO
All of
Dell OptiPlex 5050 Firmware<1.31.0
Dell OptiPlex 5050 Firmware
All of
Dell OptiPlex 3050 AIO Firmware<1.34.0
Dell OptiPlex 3050 AIO
All of
Dell OptiPlex 3050 Firmware<1.31.0
Dell OptiPlex 3050 Firmware
All of
Dell Latitude 7490 Firmware<1.39.0
Dell Latitude 7490 Firmware
All of
Dell Latitude 7480 Firmware<1.38.0
Dell Latitude 7480 Firmware
All of
Dell Latitude 7424 Rugged Extreme Firmware<1.34.0
Dell Latitude 7424 Rugged Extreme Firmware
All of
Dell Latitude 7414 Rugged Firmware<1.47.0
Dell Latitude 7414 Rugged Firmware
All of
Dell Latitude 13 7390 2-in-1 Firmware<1.36.0
Dell Latitude 7390
All of
Dell Latitude 7390 Firmware<1.39.0
Dell Latitude 7390 Firmware
All of
Dell Latitude 7380 Firmware<1.38.0
Dell Latitude 7380 Firmware
All of
Dell Latitude 7290 Firmware<1.39.0
Dell Latitude 7290 Firmware
All of
Dell Latitude 7285 2-in-1 Firmware<1.27.0
Dell Latitude 7285
All of
Dell Latitude 7280 Firmware<1.38.0
Dell Latitude 7280 Firmware
All of
Dell Latitude 7212 Rugged Extreme Tablet Firmware<1.51.0
Dell Latitude 7212 Rugged Extreme Tablet Firmware
All of
Dell Latitude 5590 Firmware<1.36.0
Dell Latitude 5590 Firmware
All of
Dell Latitude 5580 firmware<1.37.0
Dell Latitude 5580 firmware
All of
Dell Latitude 5490 Firmware<1.36.0
Dell Latitude 5490 Firmware
All of
Dell Latitude 5488 Firmware<1.37.0
Dell Latitude 5488 Firmware
All of
Dell Latitude 5480 Firmware<1.37.0
Dell Latitude 5480 Firmware
All of
Dell Latitude Rugged 5424 Firmware<1.34.0
Dell Latitude Rugged 5424 Firmware
All of
Dell Latitude Rugged 5420 Firmware<1.34.0
Dell Latitude Rugged 5420 Firmware
All of
Dell Latitude 14 Rugged 5414 Firmware<1.47.0
Dell Latitude Rugged 5414
All of
Dell Latitude 5400 Firmware<1.32.0
Dell Latitude 5400 Firmware
All of
Dell Latitude 5290 Firmware<1.36.0
Dell Latitude 5290 2-in-1
All of
Dell Latitude 5288 Firmware<1.37.0
Dell Latitude 5288 Firmware
All of
Dell Latitude 5280 Firmware<1.37.0
Dell Latitude 5280 Firmware
All of
Dell Latitude 3390 2-in-1 Firmware<1.32.0
Dell Latitude 3390
All of
Dell Latitude 3300 Firmware<1.29.0
Dell Latitude 3300 Firmware
All of
Dell Latitude 3380 Firmware<1.28.0
Dell Latitude 3380 Firmware
All of
Dell Latitude 12 Rugged Extreme 7214<1.47.0
Dell Latitude 12 Rugged Extreme 7214 Firmware
All of
Dell Embedded Box PC 5000<1.26.0
Dell Embedded Box PC 5000

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-38483?

    CVE-2024-38483 is classified as a high severity vulnerability due to its potential for code execution by a privileged attacker with local access.

  • How can I mitigate CVE-2024-38483?

    To mitigate CVE-2024-38483, ensure that affected Dell firmware is updated to the latest version that addresses the vulnerability.

  • Which Dell products are affected by CVE-2024-38483?

    CVE-2024-38483 affects specific Dell products including Latitude, Precision, Wyse, and OptiPlex models with firmware versions prior to specified limits.

  • Can CVE-2024-38483 be exploited remotely?

    No, CVE-2024-38483 requires local access to the affected system for exploitation.

  • What type of vulnerability is CVE-2024-38483?

    CVE-2024-38483 is an improper input validation vulnerability found in an externally developed component of Dell BIOS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203