DSA-2024-020: Security Update for Dell Client Platform for an Improper Input Validation Vulnerability (2024)

Impact

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-22429 Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution. 7.5
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HDSA-2024-020: Security Update for Dell Client Platform for an Improper Input Validation Vulnerability (1)
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-22429 Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution. 7.5
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HDSA-2024-020: Security Update for Dell Client Platform for an Improper Input Validation Vulnerability (2)

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Software/Firmware Affected Version Remediated Version Release Date (MM/DD/YYYY) Link
Dell Precision 5820 Tower BIOS Versions prior to 2.36.0 Versions 2.36.0 or later 05/10/2024
Edge Gateway 3000 series BIOS Versions prior to 1.18.0 Versions 1.18.0 or later 05/13/2024
Latitude 12 Rugged Extreme 7214 BIOS Versions prior to 1.46.0 Versions 1.46.0 or later 05/08/2024
Latitude 13 3380 BIOS Versions prior to 1.27.0 Versions 1.27.0 or later 05/06/2024
Latitude 3180 BIOS Versions prior to 1.29.0 Versions 1.29.0 or later 05/07/2024
Latitude 3189 BIOS Versions prior to 1.29.0 Versions 1.29.0 or later 05/07/2024
Latitude 3300 BIOS Versions prior to 1.28.0 Versions 1.28.0 or later 05/06/2024
Latitude 3390 2-in-1 BIOS Versions prior to 1.31.0 Versions 1.31.0 or later 05/06/2024
Latitude 5414 Rugged BIOS Versions prior to 1.46.0 Versions 1.46.0 or later 05/08/2024
Latitude 5420 Rugged BIOS Versions prior to 1.32.0 Versions 1.32.0 or later 05/08/2024
Latitude 5424 Rugged BIOS Versions prior to 1.32.0 Versions 1.32.0 or later 05/08/2024
Latitude 7212 Rugged Extreme Tablet BIOS Versions prior to 1.50.0 Versions 1.50.0 or later 05/08/2024
Latitude 7414 Rugged BIOS Versions prior to 1.46.0 Versions 1.46.0 or later 05/08/2024
Latitude 7424 Rugged Extreme BIOS Versions prior to 1.32.0 Versions 1.32.0 or later 05/08/2024
Precision 3420 Tower BIOS Versions prior to 2.30.0 Versions 2.30.0 or later 05/13/2024
Precision 3620 Tower BIOS Versions prior to 2.30.0 Versions 2.30.0 or later 05/13/2024
Wyse 5070 BIOS Versions prior to 1.31.0 Versions 1.31.0 or later 05/10/2024
Product Software/Firmware Affected Version Remediated Version Release Date (MM/DD/YYYY) Link
Dell Precision 5820 Tower BIOS Versions prior to 2.36.0 Versions 2.36.0 or later 05/10/2024
Edge Gateway 3000 series BIOS Versions prior to 1.18.0 Versions 1.18.0 or later 05/13/2024
Latitude 12 Rugged Extreme 7214 BIOS Versions prior to 1.46.0 Versions 1.46.0 or later 05/08/2024
Latitude 13 3380 BIOS Versions prior to 1.27.0 Versions 1.27.0 or later 05/06/2024
Latitude 3180 BIOS Versions prior to 1.29.0 Versions 1.29.0 or later 05/07/2024
Latitude 3189 BIOS Versions prior to 1.29.0 Versions 1.29.0 or later 05/07/2024
Latitude 3300 BIOS Versions prior to 1.28.0 Versions 1.28.0 or later 05/06/2024
Latitude 3390 2-in-1 BIOS Versions prior to 1.31.0 Versions 1.31.0 or later 05/06/2024
Latitude 5414 Rugged BIOS Versions prior to 1.46.0 Versions 1.46.0 or later 05/08/2024
Latitude 5420 Rugged BIOS Versions prior to 1.32.0 Versions 1.32.0 or later 05/08/2024
Latitude 5424 Rugged BIOS Versions prior to 1.32.0 Versions 1.32.0 or later 05/08/2024
Latitude 7212 Rugged Extreme Tablet BIOS Versions prior to 1.50.0 Versions 1.50.0 or later 05/08/2024
Latitude 7414 Rugged BIOS Versions prior to 1.46.0 Versions 1.46.0 or later 05/08/2024
Latitude 7424 Rugged Extreme BIOS Versions prior to 1.32.0 Versions 1.32.0 or later 05/08/2024
Precision 3420 Tower BIOS Versions prior to 2.30.0 Versions 2.30.0 or later 05/13/2024
Precision 3620 Tower BIOS Versions prior to 2.30.0 Versions 2.30.0 or later 05/13/2024
Wyse 5070 BIOS Versions prior to 1.31.0 Versions 1.31.0 or later 05/10/2024

The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

Workarounds and Mitigations

None

Acknowledgements

CVE-2024-22429: Dell would like to thank schur of BUPT, Dubhe Lab for reporting this issue.

Revision History

RevisionDateDescription
1.02024-05-14Initial Release
2.02024-05-17Added Revision history section

Related Information

Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide

Dell Edge Gateway 3000 Series, Latitude 3180, Latitude 3189, Latitude 7212 Rugged Extreme Tablet, Latitude 7214 Rugged Extreme, Latitude 3300, Latitude 13 3380, Latitude 3390 2-in-1, Latitude 5414 Rugged, Latitude 5420 Rugged, Latitude 5424 Rugged , Latitude 7414 Rugged, Latitude 7424 Rugged Extreme, Precision 5820 Tower, Dell Precision Tower 3420, Dell Precision Tower 3620, Wyse 5070 Thin Client ...

DSA-2024-020: Security Update for Dell Client Platform for an Improper Input Validation Vulnerability (2024)
Top Articles
Latest Posts
Article information

Author: Carlyn Walter

Last Updated:

Views: 6410

Rating: 5 / 5 (70 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Carlyn Walter

Birthday: 1996-01-03

Address: Suite 452 40815 Denyse Extensions, Sengermouth, OR 42374

Phone: +8501809515404

Job: Manufacturing Technician

Hobby: Table tennis, Archery, Vacation, Metal detecting, Yo-yoing, Crocheting, Creative writing

Introduction: My name is Carlyn Walter, I am a lively, glamorous, healthy, clean, powerful, calm, combative person who loves writing and wants to share my knowledge and understanding with you.