Use of hard-coded cryptographic key in Dell products - CVE-2024-39584

 

Use of hard-coded cryptographic key in Dell products - CVE-2024-39584

Published: August 28, 2024 / Updated: August 30, 2024


Vulnerability identifier: #VU96591
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-39584
CWE-ID: CWE-321
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass Secure Boot.

The vulnerability exists due to usage of a hard-coded cryptographic key. A local user can bypass Secure Boot restrictions and escalate privileges on the system.


Affected software

Alienware Aurora R15 AMD
Alienware x14
Alienware x15 R2
Alienware x17 R2
Alienware m15 R4
Alienware m17 R4
Alienware x15 R1
Alienware x17 R1
Alienware Area 51m R2
Alienware m15 R3
Alienware m17 R3

How to mitigate CVE-2024-39584

Install updates from vendor's website.

Alienware Aurora R15 AMD - update to 1.15.0
Alienware x14 - update to 1.21.0
Alienware x15 R2 - update to 1.22.0
Alienware x17 R2 - update to 1.22.0
Alienware m15 R4 - update to 1.24.0
Alienware m17 R4 - update to 1.24.0
Alienware x15 R1 - update to 1.24.0
Alienware x17 R1 - update to 1.24.0
Alienware Area 51m R2 - update to 1.29.0
Alienware m15 R3 - update to 1.29.0
Alienware m17 R3 - update to 1.29.0

External References

Related Security Bulletins