Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE-ID | CVE-2024-24852 CVE-2024-36274 |
CWE-ID | CWE-426 CWE-787 |
Exploitation vector | Local network |
Public exploit | N/A |
Vulnerable software |
Vostro 5090 Hardware solutions / Firmware OptiPlex 7760 All-In-One Hardware solutions / Firmware OptiPlex 7460 All In One Hardware solutions / Firmware OptiPlex 7450 All-In-One Hardware solutions / Firmware OptiPlex 5260 All-In-One Hardware solutions / Firmware OptiPlex 5060 Hardware solutions / Firmware OptiPlex 5050 Hardware solutions / Firmware Latitude 7414 Rugged Hardware solutions / Firmware Latitude 5414 Rugged Hardware solutions / Firmware Precision 3620 Tower Hardware solutions / Firmware Precision 3420 Tower Hardware solutions / Firmware Precision 7720 Hardware solutions / Firmware Precision 7520 Hardware solutions / Firmware Precision 3530 Hardware solutions / Firmware Precision 3520 Hardware solutions / Firmware Latitude 5591 Hardware solutions / Firmware Latitude 5590 Hardware solutions / Firmware Latitude 5580 Hardware solutions / Firmware Latitude 5491 Hardware solutions / Firmware Latitude 5490 Hardware solutions / Firmware Latitude 5488 Hardware solutions / Firmware Latitude 5480 Hardware solutions / Firmware Latitude 5290 Hardware solutions / Firmware Latitude 12 Rugged Extreme 7214 Hardware solutions / Firmware Precision 7730 Hardware solutions / Firmware Precision 7530 Hardware solutions / Firmware OptiPlex 7770 All-In-One Hardware solutions / Firmware OptiPlex 7470 All-In-One Hardware solutions / Firmware OptiPlex 7070 Ultra Hardware solutions / Firmware OptiPlex 5480 All-In-One Hardware solutions / Firmware OptiPlex 5270 All-In-One Hardware solutions / Firmware OptiPlex 5070 Hardware solutions / Firmware Dell Precision 3630 Tower Hardware solutions / Firmware Dell Precision 3431 Tower Hardware solutions / Firmware Dell Precision 3430 Tower Hardware solutions / Firmware Precision 7740 Hardware solutions / Firmware Precision 7540 Hardware solutions / Firmware Precision 3541 Hardware solutions / Firmware Precision 3540 Hardware solutions / Firmware Latitude 7490 Hardware solutions / Firmware Latitude 7480 Hardware solutions / Firmware Latitude 7390 Hardware solutions / Firmware Latitude 7380 Hardware solutions / Firmware Latitude 7290 Hardware solutions / Firmware Latitude 7280 Hardware solutions / Firmware Latitude 5501 Hardware solutions / Firmware Latitude 5500 Hardware solutions / Firmware Latitude 5401 Hardware solutions / Firmware Latitude 5400 Hardware solutions / Firmware Vostro 5880 Hardware solutions / Firmware Precision 7750 Hardware solutions / Firmware Precision 7550 Hardware solutions / Firmware Precision 3640 Hardware solutions / Firmware Precision 3551 Hardware solutions / Firmware Precision 3440 Hardware solutions / Firmware OptiPlex 7780 All-in-One Hardware solutions / Firmware OptiPlex 7480 All-in-One Hardware solutions / Firmware OptiPlex 7080 Hardware solutions / Firmware OptiPlex 5080 Hardware solutions / Firmware Latitude 5511 Hardware solutions / Firmware Latitude 5411 Hardware solutions / Firmware Inspiron 3881 Hardware solutions / Firmware Precision 3240 Compact Hardware solutions / Other hardware appliances OptiPlex XE3 Hardware solutions / Other hardware appliances OptiPlex 7071 Hardware solutions / Other hardware appliances OptiPlex 7070 Hardware solutions / Other hardware appliances OptiPlex 7060 Hardware solutions / Other hardware appliances Embedded Box PC 5000 Hardware solutions / Other hardware appliances Embedded Box PC 3000 Hardware solutions / Other hardware appliances Intel PCIe Ethernet Controller Driver Hardware solutions / Drivers |
Vendor | Dell |
Security Bulletin
This security bulletin contains information about 2 vulnerabilities.
EUVDB-ID: #VU104010
Risk: Low
CVSSv4.0: 2 [CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-24852
CWE-ID:
CWE-426 - Untrusted Search Path
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path. A local user can execute arbitrary code with escalated privileges.
MitigationInstall update from vendor's website.
Vulnerable software versionsVostro 5090: All versions
OptiPlex 7760 All-In-One: All versions
OptiPlex 7460 All In One: All versions
OptiPlex 7450 All-In-One: All versions
OptiPlex 5260 All-In-One: All versions
OptiPlex 5060: All versions
OptiPlex 5050: All versions
Latitude 7414 Rugged: All versions
Latitude 5414 Rugged: All versions
Precision 3620 Tower: All versions
Precision 3420 Tower: All versions
Precision 7720: All versions
Precision 7520: All versions
Precision 3530: All versions
Precision 3520: All versions
Latitude 5591: All versions
Latitude 5590: All versions
Latitude 5580: All versions
Latitude 5491: All versions
Latitude 5490: All versions
Latitude 5488: All versions
Latitude 5480: All versions
Latitude 5290: All versions
Latitude 12 Rugged Extreme 7214: All versions
Precision 7730: All versions
Precision 7530: All versions
OptiPlex 7770 All-In-One: All versions
OptiPlex 7470 All-In-One: All versions
OptiPlex 7070 Ultra: All versions
OptiPlex 5480 All-In-One: All versions
OptiPlex 5270 All-In-One: All versions
OptiPlex 5070: All versions
Dell Precision 3630 Tower: All versions
Dell Precision 3431 Tower: All versions
Dell Precision 3430 Tower: All versions
Precision 3240 Compact: All versions
OptiPlex XE3: All versions
OptiPlex 7071: All versions
OptiPlex 7070: All versions
OptiPlex 7060: All versions
Embedded Box PC 5000: All versions
Embedded Box PC 3000: All versions
Precision 7740: All versions
Precision 7540: All versions
Precision 3541: All versions
Precision 3540: All versions
Latitude 7490: All versions
Latitude 7480: All versions
Latitude 7390: All versions
Latitude 7380: All versions
Latitude 7290: All versions
Latitude 7280: All versions
Latitude 5501: All versions
Latitude 5500: All versions
Latitude 5401: All versions
Latitude 5400: All versions
Vostro 5880: All versions
Precision 7750: All versions
Precision 7550: All versions
Precision 3640: All versions
Precision 3551: All versions
Precision 3440: All versions
OptiPlex 7780 All-in-One: All versions
OptiPlex 7480 All-in-One: All versions
OptiPlex 7080: All versions
OptiPlex 5080: All versions
Latitude 5511: All versions
Latitude 5411: All versions
Inspiron 3881: All versions
Intel PCIe Ethernet Controller Driver: before 14.0.5.0
CPE2.3https://www.dell.com/support/kbdoc/nl-nl/000228320/dsa-2024-384
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU104011
Risk: Medium
CVSSv4.0: 4.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-36274
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the Intel 800 Series Ethernet Driver. A remote attacker on the local network can trigger an out-of-bounds write and perform a denial of service (DoS) attack.
MitigationInstall update from vendor's website.
Vulnerable software versionsVostro 5090: All versions
OptiPlex 7760 All-In-One: All versions
OptiPlex 7460 All In One: All versions
OptiPlex 7450 All-In-One: All versions
OptiPlex 5260 All-In-One: All versions
OptiPlex 5060: All versions
OptiPlex 5050: All versions
Latitude 7414 Rugged: All versions
Latitude 5414 Rugged: All versions
Precision 3620 Tower: All versions
Precision 3420 Tower: All versions
Precision 7720: All versions
Precision 7520: All versions
Precision 3530: All versions
Precision 3520: All versions
Latitude 5591: All versions
Latitude 5590: All versions
Latitude 5580: All versions
Latitude 5491: All versions
Latitude 5490: All versions
Latitude 5488: All versions
Latitude 5480: All versions
Latitude 5290: All versions
Latitude 12 Rugged Extreme 7214: All versions
Precision 7730: All versions
Precision 7530: All versions
OptiPlex 7770 All-In-One: All versions
OptiPlex 7470 All-In-One: All versions
OptiPlex 7070 Ultra: All versions
OptiPlex 5480 All-In-One: All versions
OptiPlex 5270 All-In-One: All versions
OptiPlex 5070: All versions
Dell Precision 3630 Tower: All versions
Dell Precision 3431 Tower: All versions
Dell Precision 3430 Tower: All versions
Precision 3240 Compact: All versions
OptiPlex XE3: All versions
OptiPlex 7071: All versions
OptiPlex 7070: All versions
OptiPlex 7060: All versions
Embedded Box PC 5000: All versions
Embedded Box PC 3000: All versions
Precision 7740: All versions
Precision 7540: All versions
Precision 3541: All versions
Precision 3540: All versions
Latitude 7490: All versions
Latitude 7480: All versions
Latitude 7390: All versions
Latitude 7380: All versions
Latitude 7290: All versions
Latitude 7280: All versions
Latitude 5501: All versions
Latitude 5500: All versions
Latitude 5401: All versions
Latitude 5400: All versions
Vostro 5880: All versions
Precision 7750: All versions
Precision 7550: All versions
Precision 3640: All versions
Precision 3551: All versions
Precision 3440: All versions
OptiPlex 7780 All-in-One: All versions
OptiPlex 7480 All-in-One: All versions
OptiPlex 7080: All versions
OptiPlex 5080: All versions
Latitude 5511: All versions
Latitude 5411: All versions
Inspiron 3881: All versions
Intel PCIe Ethernet Controller Driver: before 14.0.5.0
CPE2.3https://www.dell.com/support/kbdoc/nl-nl/000228320/dsa-2024-384
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.