CVE-2024-38304

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/08/2024
Last modified:
20/12/2024

Description

Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:emc_xc_core_xcxr2_firmware:*:*:*:*:*:*:*:* 2.22.1 (excluding)
cpe:2.3:h:dell:emc_xc_core_xcxr2:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_xc_core_xc940_system_firmware:*:*:*:*:*:*:*:* 2.22.2 (excluding)
cpe:2.3:h:dell:emc_xc_core_xc940_system:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_xc_core_xc740xd2_firmware:*:*:*:*:*:*:*:* 2.22.1 (excluding)
cpe:2.3:h:dell:emc_xc_core_xc740xd2:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_xc_core_xc740xd_system_firmware:*:*:*:*:*:*:*:* 2.22.2 (excluding)
cpe:2.3:h:dell:emc_xc_core_xc740xd_system:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_xc_core_xc640_system_firmware:*:*:*:*:*:*:*:* 2.22.2 (excluding)
cpe:2.3:h:dell:emc_xc_core_xc640_system:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_xc_core_6420_system_firmware:*:*:*:*:*:*:*:* 2.22.2 (excluding)
cpe:2.3:h:dell:emc_xc_core_6420_system:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_storage_nx3340_firmware:*:*:*:*:*:*:*:* 2.22.2 (excluding)
cpe:2.3:h:dell:emc_storage_nx3340:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:emc_storage_nx3240_firmware:*:*:*:*:*:*:*:* 2.22.2 (excluding)