First published: Thu Dec 12 2024(Updated: )
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Platform BIOS | ||
All of | ||
Dell embedded box pc 3000 firmware | <1.25.0 | |
Dell embedded box pc 3000 | ||
All of | ||
Dell Edge Gateway 3001 | <1.19.0 | |
Dell Edge Gateway 3001 Firmware | ||
All of | ||
Dell Edge Gateway 3002 | <1.19.0 | |
Dell Edge Gateway 3002 Firmware | ||
All of | ||
Dell Edge Gateway 3003 | <1.19.0 | |
Dell Edge Gateway 3003 Firmware | ||
All of | ||
Dell Edge Gateway 5000 firmware | <1.29.0 | |
Dell Edge Gateway 5000 firmware | ||
All of | ||
Dell Edge Gateway 5100 | <1.29.0 | |
Dell Edge Gateway 5100 firmware | ||
All of | ||
Dell edge gateway 3000 firmware | <1.19.0 | |
Dell edge gateway 3000 | ||
All of | ||
Dell Edge Gateway 3200 firmware | <1.19.0 | |
Dell Edge Gateway 3200 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47238 has a high severity rating due to the potential for arbitrary code execution by a privileged attacker.
To mitigate CVE-2024-47238, it is recommended to update the Dell Client Platform BIOS to the latest version provided by Dell.
CVE-2024-47238 affects various Dell Edge Gateway and Embedded Box PC firmware versions up to certain releases.
CVE-2024-47238 is classified as an Improper Input Validation vulnerability within the Dell Client Platform BIOS.
CVE-2024-47238 requires local access for exploitation, thus preventing remote attacks.