ID

VAR-202412-2239


CVE

CVE-2024-47238


TITLE

Vulnerabilities in multiple Dell products

Trust: 0.8

sources: JVNDB: JVNDB-2024-018568

DESCRIPTION

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. Embedded Box PC 3000 firmware, Dell Edge Gateway 3001 firmware, Dell Edge Gateway 3002 Unspecified vulnerabilities exist in multiple Dell products, including firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2024-47238 // JVNDB: JVNDB-2024-018568

AFFECTED PRODUCTS

vendor:dellmodel:edge gateway 5100scope:ltversion:1.29.0

Trust: 1.0

vendor:dellmodel:embedded box pc 3000scope:ltversion:1.25.0

Trust: 1.0

vendor:dellmodel:edge gateway 3200scope:ltversion:1.19.0

Trust: 1.0

vendor:dellmodel:edge gateway 3002scope:ltversion:1.19.0

Trust: 1.0

vendor:dellmodel:edge gateway 3003scope:ltversion:1.19.0

Trust: 1.0

vendor:dellmodel:edge gateway 3001scope:ltversion:1.19.0

Trust: 1.0

vendor:dellmodel:edge gateway 5000scope:ltversion:1.29.0

Trust: 1.0

vendor:dellmodel:edge gateway 3000scope:ltversion:1.19.0

Trust: 1.0

vendor:デルmodel:dell edge gateway 3000scope: - version: -

Trust: 0.8

vendor:デルmodel:edge gateway 5100scope: - version: -

Trust: 0.8

vendor:デルmodel:embedded box pc 3000scope: - version: -

Trust: 0.8

vendor:デルmodel:dell edge gateway 3003scope: - version: -

Trust: 0.8

vendor:デルmodel:dell edge gateway 5000scope: - version: -

Trust: 0.8

vendor:デルmodel:edge gateway 3200scope: - version: -

Trust: 0.8

vendor:デルmodel:dell edge gateway 3002scope: - version: -

Trust: 0.8

vendor:デルmodel:dell edge gateway 3001scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2024-018568 // NVD: CVE-2024-47238

CVSS

SEVERITY

CVSSV2

CVSSV3

security_alert@emc.com: CVE-2024-47238
value: HIGH

Trust: 1.0

nvd@nist.gov: CVE-2024-47238
value: MEDIUM

Trust: 1.0

NVD: CVE-2024-47238
value: MEDIUM

Trust: 0.8

security_alert@emc.com: CVE-2024-47238
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 6.0
version: 3.1

Trust: 1.0

nvd@nist.gov: CVE-2024-47238
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2024-47238
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2024-018568 // NVD: CVE-2024-47238 // NVD: CVE-2024-47238

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-20

Trust: 1.0

problemtype:Inappropriate input confirmation (CWE-20) [ others ]

Trust: 0.8

problemtype: Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-018568 // NVD: CVE-2024-47238

EXTERNAL IDS

db:NVDid:CVE-2024-47238

Trust: 2.6

db:JVNDBid:JVNDB-2024-018568

Trust: 0.8

sources: JVNDB: JVNDB-2024-018568 // NVD: CVE-2024-47238

REFERENCES

url:https://www.dell.com/support/kbdoc/en-us/000227595/dsa-2024-355

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-47238

Trust: 0.8

sources: JVNDB: JVNDB-2024-018568 // NVD: CVE-2024-47238

SOURCES

db:JVNDBid:JVNDB-2024-018568
db:NVDid:CVE-2024-47238

LAST UPDATE DATE

2025-02-11T23:12:29.642000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2024-018568date:2025-02-10T07:44:00
db:NVDid:CVE-2024-47238date:2025-02-04T15:52:06.230

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2024-018568date:2025-02-10T00:00:00
db:NVDid:CVE-2024-47238date:2024-12-12T18:15:25.250