CVE-2024-0158

MEDIUMCVSS 6.7/10EPSS 0.15%

Last modified

CVE-2024-0158 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges. EPSS estimates a 0.15% chance of exploitation in the next 30 days.

Description

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.15%

4.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellAlienware M15 R6 Firmware< 1.28.0
DellAlienware M15 R7 Firmware< 1.28.0
DellAlienware M16 R1 Firmware< 1.15.0
DellAlienware M18 R1 Firmware< 1.15.0
DellAlienware M18 R2 Firmware< 1.2.1
DellAlienware X14 R2 Firmware< 1.12.1
DellAlienware X16 R1 Firmware< 1.12.1
DellAlienware X16 R2 Firmware< 1.2.0
DellChengming 3900 Firmware< 1.20.0
DellChengming 3910 Firmware< 1.12.0
DellChengming 3911 Firmware< 1.12.0
DellChengming 3990 Firmware< 1.26.0
DellChengming 3991 Firmware< 1.26.0
DellEdge Gateway 5000 Firmware< 1.27.0
DellG15 5510 Firmware< 1.23.0
DellG15 5511 Firmware< 1.27.0
DellG15 5520 Firmware< 1.23.0
DellG15 5530 Firmware< 1.13.0
DellG16 7620 Firmware< 1.23.0
DellG16 7630 Firmware< 1.13.0
DellG3 3500 Firmware< 1.29.0
DellG5 5000 Firmware< 1.19.0
DellG5 5090 Firmware< 1.25.0
DellG5 5500 Firmware< 1.29.0
DellG7 7500 Firmware< 1.31.0
DellG7 7700 Firmware< 1.31.0
DellPrecision 3430 Tower Firmware< 1.29.0
DellPrecision 3431 Tower Firmware< 1.25.0
DellPrecision 3630 Tower Firmware< 2.27.0
DellPrecision 5820 Tower Firmware< 2.35.0
DellPrecision 7820 Tower Firmware< 2.39.0
DellPrecision 7920 Tower Firmware< 2.39.0
DellEdge Gateway 3000 Firmware< 1.17.0
DellEmbedded Box Pc 3000 Firmware< 1.23.0
DellEmbedded Box Pc 5000 Firmware< 1.24.0
DellInspiron 13 5310 Firmware< 2.26.0
DellInspiron 13 5320 Firmware< 1.17.0
DellInspiron 13 5330 Firmware< 1.13.1
DellInspiron 14 5410 Firmware< 2.25.0
DellInspiron 14 5418 Firmware< 2.25.0
DellInspiron 14 5420 Firmware< 1.20.0
DellInspiron 14 5430 Firmware< 1.12.0
DellInspiron 14 5440 Firmware< 1.3.1
DellInspiron 14 7420 2-In-1 Firmware< 1.18.0
DellInspiron 14 7430 2-In-1 Firmware< 1.12.0
DellInspiron 14 7440 2-In-1 Firmware< 1.3.1
DellInspiron 14 Plus 7420 Firmware< 1.21.0
DellInspiron 14 Plus 7430 Firmware< 1.13.0
DellInspiron 15 3511 Firmware< 1.27.0
DellInspiron 15 3520 Firmware< 1.22.0

Showing 50 of 388 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2024-0158?
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
How severe is CVE-2024-0158?
CVE-2024-0158 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.15% probability of exploitation in the next 30 days.
How do I fix CVE-2024-0158?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-0158?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST