CVE-2024-0160

MEDIUM
Published Jun 12, 2024 Modified Nov 21, 2024 CWE-863

Description

Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.

Is your site exposed to CVE-2024-0160?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.8
MEDIUM
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-863 Incorrect Authorization

Affected Products

Vendor Product
dell xps_17_9700_firmware
dell xps_17_9700
dell xps_15_9500_firmware
dell xps_15_9500
dell vostro_7500_firmware
dell vostro_7500
dell precision_5750_firmware
dell precision_5750
dell precision_5550_firmware
dell precision_5550
dell latitude_3520_firmware
dell latitude_3520
dell latitude_3510_firmware
dell latitude_3510
dell latitude_3420_firmware
dell latitude_3420
dell latitude_3410_firmware
dell latitude_3410
dell inspiron_7501_firmware
dell inspiron_7501
dell inspiron_7500_firmware
dell inspiron_7500
dell g7_7700_firmware
dell g7_7700
dell g7_7500_firmware
dell g7_7500
dell g5_5500_firmware
dell g5_5500
dell g3_3500_firmware
dell g3_3500

References

Frequently Asked Questions

What is CVE-2024-0160? +
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS. It has a CVSS v3.1 base score of 6.8 (MEDIUM).
How severe is CVE-2024-0160? +
CVE-2024-0160 has a CVSS v3.1 score of 6.8 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-0160? +
CVE-2024-0160 affects products from dell, specifically: g3_3500, g3_3500_firmware, g5_5500, g5_5500_firmware, g7_7500, g7_7500_firmware, g7_7700, g7_7700_firmware, inspiron_7500, inspiron_7500_firmware, inspiron_7501, inspiron_7501_firmware, latitude_3410, latitude_3410_firmware, latitude_3420, latitude_3420_firmware, latitude_3510, latitude_3510_firmware, latitude_3520, latitude_3520_firmware, precision_5550, precision_5550_firmware, precision_5750, precision_5750_firmware, vostro_7500, vostro_7500_firmware, xps_15_9500, xps_15_9500_firmware, xps_17_9700, xps_17_9700_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-0160? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-0160 — free, no signup required.