Dell Alienware Aurora Ryzen Edition R14 Firmware vulnerabilities

6 known vulnerabilities affecting dell/alienware_aurora_ryzen_edition_r14_firmware.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2024-39584HIGHCVSS 8.2fixed in 2.19.12024-08-28
CVE-2024-39584 [HIGH] CWE-1392 CVE-2024-39584: Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privile Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.
nvd
CVE-2024-32859HIGHCVSS 8.2fixed in 2.18.02024-06-13
CVE-2024-32859 [HIGH] CWE-20 CVE-2024-32859: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-32858HIGHCVSS 8.2fixed in 2.18.02024-06-13
CVE-2024-32858 [HIGH] CWE-20 CVE-2024-32858: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-32860HIGHCVSS 8.2fixed in 2.18.02024-06-13
CVE-2024-32860 [HIGH] CWE-20 CVE-2024-32860: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-32856MEDIUMCVSS 6.0fixed in 2.18.02024-06-13
CVE-2024-32856 [MEDIUM] CWE-20 CVE-2024-32856: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2023-32475HIGHCVSS 7.6fixed in 2.16.02024-06-07
CVE-2023-32475 [HIGH] CWE-353 CVE-2023-32475: Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical ac Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system.
nvd