CVE-2024-47238
https://notcve.org/view.php?id=CVE-2024-47238
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. • https://www.dell.com/support/kbdoc/en-us/000227595/dsa-2024-355 • CWE-20: Improper Input Validation •
CVE-2024-52537
https://notcve.org/view.php?id=CVE-2024-52537
Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. • https://www.dell.com/support/kbdoc/en-us/000227591/dsa-2024-351 • CWE-61: UNIX Symbolic Link (Symlink) Following •
CVE-2024-39584
https://notcve.org/view.php?id=CVE-2024-39584
Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution. • https://www.dell.com/support/kbdoc/en-us/000227594/dsa-2024-354 • CWE-1392: Use of Default Credentials •
CVE-2024-38483
https://notcve.org/view.php?id=CVE-2024-38483
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. • https://www.dell.com/support/kbdoc/en-us/000225776/dsa-2024-260 • CWE-20: Improper Input Validation •