MEDIUM · 6.8

CVE-2024-0160

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to m...

Vulnerability Description

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DellXps 17 9700 Firmware< 1.30.0
DellXps 17 9700-
DellXps 15 9500 Firmware< 1.31.0
DellXps 15 9500-
DellVostro 7500 Firmware< 1.28.0
DellVostro 7500-
DellPrecision 5750 Firmware< 1.30.0
DellPrecision 5750-
DellPrecision 5550 Firmware< 1.31.0
DellPrecision 5550-
DellLatitude 3520 Firmware< 1.36.0
DellLatitude 3520-
DellLatitude 3510 Firmware< 1.29.0
DellLatitude 3510-
DellLatitude 3420 Firmware< 1.36.0
DellLatitude 3420-
DellLatitude 3410 Firmware< 1.29.0
DellLatitude 3410-
DellInspiron 7501 Firmware< 1.28.0
DellInspiron 7501-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-0160?

CVE-2024-0160 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to m...

How severe is CVE-2024-0160?

CVE-2024-0160 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-0160?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Xps 17 9700 Firmware, Dell Xps 17 9700, Dell Xps 15 9500 Firmware, Dell Xps 15 9500, Dell Vostro 7500 Firmware.