CVE-2024-38303
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
29/08/2024
Last modified:
20/12/2024
Description
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dell:emc_xc_core_xcxr2_firmware:*:*:*:*:*:*:*:* | 2.22.1 (excluding) | |
| cpe:2.3:h:dell:emc_xc_core_xcxr2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_xc_core_xc940_system_firmware:*:*:*:*:*:*:*:* | 2.22.2 (excluding) | |
| cpe:2.3:h:dell:emc_xc_core_xc940_system:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_xc_core_xc740xd2_firmware:*:*:*:*:*:*:*:* | 2.22.1 (excluding) | |
| cpe:2.3:h:dell:emc_xc_core_xc740xd2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_xc_core_xc740xd_system_firmware:*:*:*:*:*:*:*:* | 2.22.2 (excluding) | |
| cpe:2.3:h:dell:emc_xc_core_xc740xd_system:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_xc_core_xc640_system_firmware:*:*:*:*:*:*:*:* | 2.22.2 (excluding) | |
| cpe:2.3:h:dell:emc_xc_core_xc640_system:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_xc_core_6420_system_firmware:*:*:*:*:*:*:*:* | 2.22.2 (excluding) | |
| cpe:2.3:h:dell:emc_xc_core_6420_system:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_storage_nx3340_firmware:*:*:*:*:*:*:*:* | 2.22.2 (excluding) | |
| cpe:2.3:h:dell:emc_storage_nx3340:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:emc_storage_nx3240_firmware:*:*:*:*:*:*:*:* | 2.22.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



