Input validation error in Dell BIOS - CVE-2024-22429
Published: June 25, 2024
Vulnerability identifier: #VU93217
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22429
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local privileged user to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A local authenticated user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.
Affected software
Dell BIOS
PowerEdge T30 Mini Tower Server
PowerEdge T30 Mini Tower Server
How to mitigate CVE-2024-22429
Install updates from vendor's website.
PowerEdge T30 Mini Tower Server - update to 1.15.0