CVE-2024-0158

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
02/07/2024
Last modified:
31/07/2024

Description

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:alienware_m15_r6_firmware:*:*:*:*:*:*:*:* 1.28.0 (excluding)
cpe:2.3:h:dell:alienware_m15_r6:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_m15_r7_firmware:*:*:*:*:*:*:*:* 1.28.0 (excluding)
cpe:2.3:h:dell:alienware_m15_r7:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_m16_r1_firmware:*:*:*:*:*:*:*:* 1.15.0 (excluding)
cpe:2.3:h:dell:alienware_m16_r1:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_m18_r1_firmware:*:*:*:*:*:*:*:* 1.15.0 (excluding)
cpe:2.3:h:dell:alienware_m18_r1:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_m18_r2_firmware:*:*:*:*:*:*:*:* 1.2.1 (excluding)
cpe:2.3:h:dell:alienware_m18_r2:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_x14_r2_firmware:*:*:*:*:*:*:*:* 1.12.1 (excluding)
cpe:2.3:h:dell:alienware_x14_r2:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_x16_r1_firmware:*:*:*:*:*:*:*:* 1.12.1 (excluding)
cpe:2.3:h:dell:alienware_x16_r1:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_x16_r2_firmware:*:*:*:*:*:*:*:* 1.2.0 (excluding)