Dell Client Platform update for Intel Ethernet Adapter Complete Driver Pack



Risk Medium
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2024-24852
CVE-2024-36274
CWE-ID CWE-426
CWE-787
Exploitation vector Local network
Public exploit N/A
Vulnerable software
Vostro 5090
Hardware solutions / Firmware

OptiPlex 7760 All-In-One
Hardware solutions / Firmware

OptiPlex 7460 All In One
Hardware solutions / Firmware

OptiPlex 7450 All-In-One
Hardware solutions / Firmware

OptiPlex 5260 All-In-One
Hardware solutions / Firmware

OptiPlex 5060
Hardware solutions / Firmware

OptiPlex 5050
Hardware solutions / Firmware

Latitude 7414 Rugged
Hardware solutions / Firmware

Latitude 5414 Rugged
Hardware solutions / Firmware

Precision 3620 Tower
Hardware solutions / Firmware

Precision 3420 Tower
Hardware solutions / Firmware

Precision 7720
Hardware solutions / Firmware

Precision 7520
Hardware solutions / Firmware

Precision 3530
Hardware solutions / Firmware

Precision 3520
Hardware solutions / Firmware

Latitude 5591
Hardware solutions / Firmware

Latitude 5590
Hardware solutions / Firmware

Latitude 5580
Hardware solutions / Firmware

Latitude 5491
Hardware solutions / Firmware

Latitude 5490
Hardware solutions / Firmware

Latitude 5488
Hardware solutions / Firmware

Latitude 5480
Hardware solutions / Firmware

Latitude 5290
Hardware solutions / Firmware

Latitude 12 Rugged Extreme 7214
Hardware solutions / Firmware

Precision 7730
Hardware solutions / Firmware

Precision 7530
Hardware solutions / Firmware

OptiPlex 7770 All-In-One
Hardware solutions / Firmware

OptiPlex 7470 All-In-One
Hardware solutions / Firmware

OptiPlex 7070 Ultra
Hardware solutions / Firmware

OptiPlex 5480 All-In-One
Hardware solutions / Firmware

OptiPlex 5270 All-In-One
Hardware solutions / Firmware

OptiPlex 5070
Hardware solutions / Firmware

Dell Precision 3630 Tower
Hardware solutions / Firmware

Dell Precision 3431 Tower
Hardware solutions / Firmware

Dell Precision 3430 Tower
Hardware solutions / Firmware

Precision 7740
Hardware solutions / Firmware

Precision 7540
Hardware solutions / Firmware

Precision 3541
Hardware solutions / Firmware

Precision 3540
Hardware solutions / Firmware

Latitude 7490
Hardware solutions / Firmware

Latitude 7480
Hardware solutions / Firmware

Latitude 7390
Hardware solutions / Firmware

Latitude 7380
Hardware solutions / Firmware

Latitude 7290
Hardware solutions / Firmware

Latitude 7280
Hardware solutions / Firmware

Latitude 5501
Hardware solutions / Firmware

Latitude 5500
Hardware solutions / Firmware

Latitude 5401
Hardware solutions / Firmware

Latitude 5400
Hardware solutions / Firmware

Vostro 5880
Hardware solutions / Firmware

Precision 7750
Hardware solutions / Firmware

Precision 7550
Hardware solutions / Firmware

Precision 3640
Hardware solutions / Firmware

Precision 3551
Hardware solutions / Firmware

Precision 3440
Hardware solutions / Firmware

OptiPlex 7780 All-in-One
Hardware solutions / Firmware

OptiPlex 7480 All-in-One
Hardware solutions / Firmware

OptiPlex 7080
Hardware solutions / Firmware

OptiPlex 5080
Hardware solutions / Firmware

Latitude 5511
Hardware solutions / Firmware

Latitude 5411
Hardware solutions / Firmware

Inspiron 3881
Hardware solutions / Firmware

Precision 3240 Compact
Hardware solutions / Other hardware appliances

OptiPlex XE3
Hardware solutions / Other hardware appliances

OptiPlex 7071
Hardware solutions / Other hardware appliances

OptiPlex 7070
Hardware solutions / Other hardware appliances

OptiPlex 7060
Hardware solutions / Other hardware appliances

Embedded Box PC 5000
Hardware solutions / Other hardware appliances

Embedded Box PC 3000
Hardware solutions / Other hardware appliances

Intel PCIe Ethernet Controller Driver
Hardware solutions / Drivers

Vendor Dell

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Untrusted search path

EUVDB-ID: #VU104010

Risk: Low

CVSSv4.0: 2 [CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-24852

CWE-ID: CWE-426 - Untrusted Search Path

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to usage of an untrusted search path. A local user can execute arbitrary code with escalated privileges.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Vostro 5090: All versions

OptiPlex 7760 All-In-One: All versions

OptiPlex 7460 All In One: All versions

OptiPlex 7450 All-In-One: All versions

OptiPlex 5260 All-In-One: All versions

OptiPlex 5060: All versions

OptiPlex 5050: All versions

Latitude 7414 Rugged: All versions

Latitude 5414 Rugged: All versions

Precision 3620 Tower: All versions

Precision 3420 Tower: All versions

Precision 7720: All versions

Precision 7520: All versions

Precision 3530: All versions

Precision 3520: All versions

Latitude 5591: All versions

Latitude 5590: All versions

Latitude 5580: All versions

Latitude 5491: All versions

Latitude 5490: All versions

Latitude 5488: All versions

Latitude 5480: All versions

Latitude 5290: All versions

Latitude 12 Rugged Extreme 7214: All versions

Precision 7730: All versions

Precision 7530: All versions

OptiPlex 7770 All-In-One: All versions

OptiPlex 7470 All-In-One: All versions

OptiPlex 7070 Ultra: All versions

OptiPlex 5480 All-In-One: All versions

OptiPlex 5270 All-In-One: All versions

OptiPlex 5070: All versions

Dell Precision 3630 Tower: All versions

Dell Precision 3431 Tower: All versions

Dell Precision 3430 Tower: All versions

Precision 3240 Compact: All versions

OptiPlex XE3: All versions

OptiPlex 7071: All versions

OptiPlex 7070: All versions

OptiPlex 7060: All versions

Embedded Box PC 5000: All versions

Embedded Box PC 3000: All versions

Precision 7740: All versions

Precision 7540: All versions

Precision 3541: All versions

Precision 3540: All versions

Latitude 7490: All versions

Latitude 7480: All versions

Latitude 7390: All versions

Latitude 7380: All versions

Latitude 7290: All versions

Latitude 7280: All versions

Latitude 5501: All versions

Latitude 5500: All versions

Latitude 5401: All versions

Latitude 5400: All versions

Vostro 5880: All versions

Precision 7750: All versions

Precision 7550: All versions

Precision 3640: All versions

Precision 3551: All versions

Precision 3440: All versions

OptiPlex 7780 All-in-One: All versions

OptiPlex 7480 All-in-One: All versions

OptiPlex 7080: All versions

OptiPlex 5080: All versions

Latitude 5511: All versions

Latitude 5411: All versions

Inspiron 3881: All versions

Intel PCIe Ethernet Controller Driver: before 14.0.5.0

CPE2.3 External links

https://www.dell.com/support/kbdoc/nl-nl/000228320/dsa-2024-384


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Out-of-bounds write

EUVDB-ID: #VU104011

Risk: Medium

CVSSv4.0: 4.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2024-36274

CWE-ID: CWE-787 - Out-of-bounds write

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in the Intel 800 Series Ethernet Driver. A remote attacker on the local network can trigger an out-of-bounds write and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Vostro 5090: All versions

OptiPlex 7760 All-In-One: All versions

OptiPlex 7460 All In One: All versions

OptiPlex 7450 All-In-One: All versions

OptiPlex 5260 All-In-One: All versions

OptiPlex 5060: All versions

OptiPlex 5050: All versions

Latitude 7414 Rugged: All versions

Latitude 5414 Rugged: All versions

Precision 3620 Tower: All versions

Precision 3420 Tower: All versions

Precision 7720: All versions

Precision 7520: All versions

Precision 3530: All versions

Precision 3520: All versions

Latitude 5591: All versions

Latitude 5590: All versions

Latitude 5580: All versions

Latitude 5491: All versions

Latitude 5490: All versions

Latitude 5488: All versions

Latitude 5480: All versions

Latitude 5290: All versions

Latitude 12 Rugged Extreme 7214: All versions

Precision 7730: All versions

Precision 7530: All versions

OptiPlex 7770 All-In-One: All versions

OptiPlex 7470 All-In-One: All versions

OptiPlex 7070 Ultra: All versions

OptiPlex 5480 All-In-One: All versions

OptiPlex 5270 All-In-One: All versions

OptiPlex 5070: All versions

Dell Precision 3630 Tower: All versions

Dell Precision 3431 Tower: All versions

Dell Precision 3430 Tower: All versions

Precision 3240 Compact: All versions

OptiPlex XE3: All versions

OptiPlex 7071: All versions

OptiPlex 7070: All versions

OptiPlex 7060: All versions

Embedded Box PC 5000: All versions

Embedded Box PC 3000: All versions

Precision 7740: All versions

Precision 7540: All versions

Precision 3541: All versions

Precision 3540: All versions

Latitude 7490: All versions

Latitude 7480: All versions

Latitude 7390: All versions

Latitude 7380: All versions

Latitude 7290: All versions

Latitude 7280: All versions

Latitude 5501: All versions

Latitude 5500: All versions

Latitude 5401: All versions

Latitude 5400: All versions

Vostro 5880: All versions

Precision 7750: All versions

Precision 7550: All versions

Precision 3640: All versions

Precision 3551: All versions

Precision 3440: All versions

OptiPlex 7780 All-in-One: All versions

OptiPlex 7480 All-in-One: All versions

OptiPlex 7080: All versions

OptiPlex 5080: All versions

Latitude 5511: All versions

Latitude 5411: All versions

Inspiron 3881: All versions

Intel PCIe Ethernet Controller Driver: before 14.0.5.0

CPE2.3 External links

https://www.dell.com/support/kbdoc/nl-nl/000228320/dsa-2024-384


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###