CVE-2024-0160
published 2024-06-12CVE-2024-0160: Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this…
PriorityP428medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.25%
16.1th percentile
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | cpg_bios | >= N/A < 1.32.0 | 1.32.0 |
| dell | g3_3500_firmware | < 1.30.0 | 1.30.0 |
| dell | g5_5500_firmware | < 1.30.0 | 1.30.0 |
| dell | g7_7500_firmware | < 1.32.0 | 1.32.0 |
| dell | g7_7700_firmware | < 1.32.0 | 1.32.0 |
| dell | inspiron_7500_firmware | < 1.28.0 | 1.28.0 |
| dell | inspiron_7501_firmware | < 1.28.0 | 1.28.0 |
| dell | latitude_3410_firmware | < 1.29.0 | 1.29.0 |
| dell | latitude_3420_firmware | < 1.36.0 | 1.36.0 |
| dell | latitude_3510_firmware | < 1.29.0 | 1.29.0 |
| dell | latitude_3520_firmware | < 1.36.0 | 1.36.0 |
| dell | precision_5550_firmware | < 1.31.0 | 1.31.0 |
| dell | precision_5750_firmware | < 1.30.0 | 1.30.0 |
| dell | vostro_7500_firmware | < 1.28.0 | 1.28.0 |
| dell | xps_15_9500_firmware | < 1.31.0 | 1.31.0 |
| dell | xps_17_9700_firmware | < 1.30.0 | 1.30.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT TLS HeartBeat Request (Server Initiated) fb set
suricata·2014-04-09
CVE-2014-0160 ET EXPLOIT TLS HeartBeat Request (Server Initiated) fb set
ET EXPLOIT TLS HeartBeat Request (Server Initiated) fb set
Rule: alert tcp any any -> $HOME_NET any (msg:"ET EXPLOIT TLS HeartBeat Request (Server Initiated) fb set"; flow:established,to_client; flowbits:isnotset,ET.HB.Response.SI; flowbits:set,ET.HB.Request.SI; flowbits:noalert; content:"|18 03|"; depth:2; byte_test:1,<,4,2; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018375; rev:6; metadata:created_at 2014_04_09, cve CVE_2014_0160, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
Suricata
ET EXPLOIT TLS HeartBeat Request (Client Initiated) fb set
suricata·2014-04-09
CVE-2014-0160 ET EXPLOIT TLS HeartBeat Request (Client Initiated) fb set
ET EXPLOIT TLS HeartBeat Request (Client Initiated) fb set
Rule: alert tcp any any -> $HOME_NET any (msg:"ET EXPLOIT TLS HeartBeat Request (Client Initiated) fb set"; flow:established,to_server; flowbits:isnotset,ET.HB.Response.CI; flowbits:set,ET.HB.Request.CI; flowbits:noalert; content:"|18 03|"; depth:2; byte_test:1,<,4,2; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018376; rev:6; metadata:created_at 2014_04_09, cve CVE_2014_0160, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
No public exploits indexed.
No writeups or analysis indexed.
2024-06-12
Published