CVE-2024-42425

Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:precision_7920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_7920:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:7920_xl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:7920_xl:-:*:*:*:*:*:*:*

History

16 Sep 2024, 15:46

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000227015/dsa-2024-328 - () https://www.dell.com/support/kbdoc/en-us/000227015/dsa-2024-328 - Vendor Advisory
CPE cpe:2.3:h:dell:7920_xl:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:precision_7920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:7920_xl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:precision_7920:-:*:*:*:*:*:*:*
First Time Dell precision 7920 Firmware
Dell precision 7920
Dell 7920 Xl Firmware
Dell 7920 Xl
Dell
CWE CWE-119
CVSS v2 : unknown
v3 : 3.8
v2 : unknown
v3 : 5.5

10 Sep 2024, 12:09

Type Values Removed Values Added
Summary
  • (es) Las versiones de BIOS de Intel para Dell Precision Rack 14G anteriores a la 2.22.2 contienen una vulnerabilidad de acceso a la ubicación de la memoria después del final del búfer. Un atacante con pocos privilegios y acceso local podría aprovechar esta vulnerabilidad, lo que provocaría la divulgación de información.

10 Sep 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-10 09:15

Updated : 2024-09-16 15:46


NVD link : CVE-2024-42425

Mitre link : CVE-2024-42425

CVE.ORG link : CVE-2024-42425


JSON object : View

Products Affected

dell

  • precision_7920_firmware
  • 7920_xl
  • 7920_xl_firmware
  • precision_7920
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-788

Access of Memory Location After End of Buffer