CVE-2024-47238

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:embedded_box_pc_3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:embedded_box_pc_3000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:edge_gateway_3001_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_3001:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dell:edge_gateway_3002_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_3002:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dell:edge_gateway_3003_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_3003:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dell:edge_gateway_5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_5000:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dell:edge_gateway_5100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_5100:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dell:edge_gateway_3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_3000:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dell:edge_gateway_3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_3200:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-12-12 18:15

Updated : 2025-02-04 15:52


NVD link : CVE-2024-47238

Mitre link : CVE-2024-47238

CVE.ORG link : CVE-2024-47238


JSON object : View

Products Affected

dell

  • embedded_box_pc_3000_firmware
  • edge_gateway_3003
  • edge_gateway_3001_firmware
  • embedded_box_pc_3000
  • edge_gateway_3002_firmware
  • edge_gateway_3200_firmware
  • edge_gateway_3001
  • edge_gateway_3002
  • edge_gateway_5100_firmware
  • edge_gateway_5100
  • edge_gateway_5000
  • edge_gateway_3000_firmware
  • edge_gateway_3000
  • edge_gateway_3003_firmware
  • edge_gateway_5000_firmware
  • edge_gateway_3200
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo