CVE-2024-38304

Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:emc_xc_core_xcxr2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:emc_xc_core_xcxr2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:emc_xc_core_xc940_system_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:emc_xc_core_xc940_system:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dell:emc_xc_core_xc740xd2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:emc_xc_core_xc740xd2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dell:emc_xc_core_xc740xd_system_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:emc_xc_core_xc740xd_system:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dell:emc_xc_core_xc640_system_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:emc_xc_core_xc640_system:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dell:emc_xc_core_6420_system_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:emc_xc_core_6420_system:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dell:emc_storage_nx3340_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:emc_storage_nx3340:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dell:emc_storage_nx3240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:emc_storage_nx3240:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dell:poweredge_xe7440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_xe7440:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dell:poweredge_xe7420_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_xe7420:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:dell:poweredge_xe2420_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_xe2420:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:dell:dss_8440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:dss_8440:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:dell:poweredge_c4140_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_c4140:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:dell:poweredge_mx840c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_mx840c:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:dell:poweredge_mx740c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_mx740c:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:dell:poweredge_m640_\(for_pe_vrtx\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_m640_\(for_pe_vrtx\):-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:dell:poweredge_m640_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_m640:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:dell:poweredge_fc640_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_fc640:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:dell:poweredge_c6420_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_c6420:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:dell:poweredge_t640_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_t640:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:dell:poweredge_r940xa_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r940xa:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:dell:poweredge_r840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r840:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:dell:poweredge_r740xd2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r740xd2:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:dell:poweredge_xr2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_xr2:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:dell:poweredge_t440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_t440:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:dell:poweredge_r440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r440:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:dell:poweredge_r540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r540:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:dell:poweredge_r940_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r940:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:dell:poweredge_r640_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r640:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:dell:poweredge_r740xd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r740xd:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:dell:poweredge_r740_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r740:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-29 11:15

Updated : 2024-12-20 14:41


NVD link : CVE-2024-38304

Mitre link : CVE-2024-38304

CVE.ORG link : CVE-2024-38304


JSON object : View

Products Affected

dell

  • emc_storage_nx3340
  • emc_xc_core_6420_system_firmware
  • poweredge_r740_firmware
  • poweredge_xe2420_firmware
  • poweredge_xe7420
  • poweredge_r940_firmware
  • poweredge_mx840c
  • emc_xc_core_xc740xd2
  • poweredge_xe2420
  • dss_8440_firmware
  • poweredge_c6420
  • poweredge_r740xd2
  • poweredge_m640_\(for_pe_vrtx\)
  • poweredge_r940xa
  • emc_xc_core_xcxr2_firmware
  • poweredge_xe7440_firmware
  • poweredge_xr2_firmware
  • poweredge_fc640
  • poweredge_r440_firmware
  • emc_xc_core_xc740xd_system_firmware
  • emc_storage_nx3340_firmware
  • emc_xc_core_xcxr2
  • poweredge_c4140
  • poweredge_t640_firmware
  • emc_xc_core_xc640_system
  • poweredge_c6420_firmware
  • poweredge_r540
  • poweredge_xe7440
  • poweredge_m640
  • poweredge_r840_firmware
  • poweredge_m640_firmware
  • emc_xc_core_xc940_system_firmware
  • poweredge_mx840c_firmware
  • emc_xc_core_xc940_system
  • emc_xc_core_xc640_system_firmware
  • poweredge_mx740c
  • poweredge_t640
  • poweredge_t440
  • poweredge_r940
  • emc_xc_core_6420_system
  • dss_8440
  • poweredge_r640_firmware
  • poweredge_r740xd
  • poweredge_r940xa_firmware
  • poweredge_r640
  • emc_xc_core_xc740xd2_firmware
  • poweredge_c4140_firmware
  • poweredge_mx740c_firmware
  • poweredge_r540_firmware
  • poweredge_m640_\(for_pe_vrtx\)_firmware
  • poweredge_r740xd_firmware
  • poweredge_t440_firmware
  • poweredge_xe7420_firmware
  • poweredge_r840
  • emc_xc_core_xc740xd_system
  • poweredge_r440
  • poweredge_r740
  • poweredge_xr2
  • emc_storage_nx3240
  • poweredge_fc640_firmware
  • poweredge_r740xd2_firmware
  • emc_storage_nx3240_firmware
CWE
CWE-788

Access of Memory Location After End of Buffer

NVD-CWE-Other