CVE-2024-0160

Severity
6.8MEDIUM
EPSS
0.0%
top 86.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 12

Description

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages16 packages

CVEListV5dell/cpg_biosN/A1.32.0
NVDdell/g3_3500_firmware< 1.30.0
NVDdell/g5_5500_firmware< 1.30.0
NVDdell/g7_7500_firmware< 1.32.0
NVDdell/g7_7700_firmware< 1.32.0

🔴Vulnerability Details

2
CVEList
CVE-2024-0160: Dell Client Platform contains an incorrect authorization vulnerability2024-06-12
GHSA
GHSA-47wc-gh7x-58g7: Dell Client Platform contains an incorrect authorization vulnerability2024-06-12