PT-2024-6020 · Dell+1 · Dell Poweredge+1

Codebreaker1337

·

Published

2024-06-13

·

Updated

2024-12-20

·

CVE-2024-38303

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell PowerEdge Platform, 14G Intel BIOS versions prior to 2.22.x
Description The issue is related to insufficient input validation in the BIOS software of Dell PowerEdge servers. This could allow an attacker with high privileges and local access to potentially disclose protected information.
Recommendations For versions prior to 2.22.x, update to version 2.22.x or later to resolve the issue. As a temporary workaround, consider restricting local access to the system to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-06830
CVE-2024-38303

Affected Products

Dell Poweredge
Intel Bios