CVE-2025-29988
published 2025-04-09CVE-2025-29988: Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this…
PriorityP431medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.17%
6.5th percentile
Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
Affected
265 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | 14_plus_2-in-1_db04250_firmware | < 1.3.2 | 1.3.2 |
| dell | 14_plus_db14250_firmware | < 1.3.2 | 1.3.2 |
| dell | 16_plus_2-in-1_db06250_firmware | < 1.3.2 | 1.3.2 |
| dell | 16_plus_db16250_firmware | < 1.3.2 | 1.3.2 |
| dell | 24_all-in-one_ec24250_firmware | < 1.4.0 | 1.4.0 |
| dell | 27_all-in-one_ec27250_firmware | < 1.4.0 | 1.4.0 |
| dell | alienware_area-51_aat2250_firmware | < 1.4.2 | 1.4.2 |
| dell | alienware_aurora_act1250_firmware | < 1.4.3 | 1.4.3 |
| dell | alienware_m15_r6_firmware | < 1.36.0 | 1.36.0 |
| dell | alienware_m15_r7_firmware | < 1.32.0 | 1.32.0 |
| dell | alienware_m16_r1_firmware | < 1.26.0 | 1.26.0 |
| dell | alienware_m16_r2_firmware | < 1.11.0 | 1.11.0 |
| dell | alienware_m18_r1_firmware | < 1.26.0 | 1.26.0 |
| dell | alienware_m18_r2_firmware | < 1.13.0 | 1.13.0 |
| dell | alienware_x14_r2_firmware | < 1.22.0 | 1.22.0 |
| dell | alienware_x16_r1_firmware | < 1.22.0 | 1.22.0 |
| dell | alienware_x16_r2_firmware | < 1.11.0 | 1.11.0 |
| dell | chengming_3900_firmware | < 1.31.0 | 1.31.0 |
| dell | chengming_3910_firmware | < 1.24.0 | 1.24.0 |
| dell | chengming_3911_firmware | < 1.24.0 | 1.24.0 |
| dell | dell_client_platform_bios | >= N/A < 2.1.5 | 2.1.5 |
| dell | dell_client_platform_bios | >= N/A < 1.35.0 | 1.35.0 |
| dell | dell_client_platform_bios | >= N/A < 2.24.0 | 2.24.0 |
| dell | dell_client_platform_bios | >= N/A < 1.33.0 | 1.33.0 |
| dell | g15_5510_firmware | < 1.31.0 | 1.31.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-09
Published