Dell Client Platform update for OpenSSL



Published: 2024-10-25
Risk Medium
Patch available YES
Number of vulnerabilities 4
CVE-ID CVE-2023-5363
CVE-2023-5678
CVE-2023-6237
CVE-2024-0727
CWE-ID CWE-310
CWE-399
CWE-476
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
XPS 13 Plus 9320
Hardware solutions / Firmware

XPS 13 9315
Hardware solutions / Firmware

Vostro 5890
Hardware solutions / Firmware

Vostro 5880
Hardware solutions / Firmware

Vostro 5090
Hardware solutions / Firmware

Vostro 3890
Hardware solutions / Firmware

Vostro 15 3530
Hardware solutions / Firmware

Vostro 15 3520
Hardware solutions / Firmware

Vostro 14 3430
Hardware solutions / Firmware

Vostro 14 3420
Hardware solutions / Firmware

Precision 3930 Rack
Hardware solutions / Firmware

Precision 3680 Tower
Hardware solutions / Firmware

Precision 3660
Hardware solutions / Firmware

Precision 3650 Tower
Hardware solutions / Firmware

Precision 3640
Hardware solutions / Firmware

Precision 3620 Tower
Hardware solutions / Firmware

Precision 3581
Hardware solutions / Firmware

Precision 3580
Hardware solutions / Firmware

Precision 3460 Small Form Factor
Hardware solutions / Firmware

Precision 3460 XE Small Form Factor
Hardware solutions / Firmware

Precision 3450
Hardware solutions / Firmware

Precision 3420 Tower
Hardware solutions / Firmware

Precision 3280 CFF
Hardware solutions / Firmware

Precision 3260 Compact
Hardware solutions / Firmware

Precision 3260 XE Compact
Hardware solutions / Firmware

OptiPlex XE4 Tower
Hardware solutions / Firmware

OptiPlex XE4 SFF
Hardware solutions / Firmware

OptiPlex Tower 7020
Hardware solutions / Firmware

OptiPlex Tower Plus 7010
Hardware solutions / Firmware

OptiPlex Tower 7010
Hardware solutions / Firmware

OptiPlex Small Form Factor Plus 7010
Hardware solutions / Firmware

OptiPlex Small Form Factor 7010
Hardware solutions / Firmware

OptiPlex SFF 7020
Hardware solutions / Firmware

OptiPlex Micro 7020
Hardware solutions / Firmware

OptiPlex Micro Plus 7010
Hardware solutions / Firmware

OptiPlex Micro 7010
Hardware solutions / Firmware

OptiPlex All-in-One 7410
Hardware solutions / Firmware

OptiPlex AIO 7420
Hardware solutions / Firmware

OptiPlex 7780 All-in-One
Hardware solutions / Firmware

OptiPlex 7770 All-In-One
Hardware solutions / Firmware

OptiPlex 7760 All-In-One
Hardware solutions / Firmware

OptiPlex 7490 All-in-One
Hardware solutions / Firmware

OptiPlex 7480 All-in-One
Hardware solutions / Firmware

OptiPlex 7470 All-In-One
Hardware solutions / Firmware

OptiPlex 7460 All In One
Hardware solutions / Firmware

OptiPlex 7450 All-In-One
Hardware solutions / Firmware

OptiPlex 7400 All-In-One
Hardware solutions / Firmware

Optiplex 7090 Ultra
Hardware solutions / Firmware

OptiPlex 7090 Tower
Hardware solutions / Firmware

OptiPlex 7000
Hardware solutions / Firmware

OptiPlex 5490 All-In-One
Hardware solutions / Firmware

OptiPlex 5480 All-In-One
Hardware solutions / Firmware

OptiPlex 5400 All-In-One
Hardware solutions / Firmware

OptiPlex 5270 All-In-One
Hardware solutions / Firmware

OptiPlex 5260 All-In-One
Hardware solutions / Firmware

OptiPlex 5090
Hardware solutions / Firmware

OptiPlex 5080
Hardware solutions / Firmware

OptiPlex 5050
Hardware solutions / Firmware

OptiPlex 5000
Hardware solutions / Firmware

OptiPlex 3280 All-in-One
Hardware solutions / Firmware

OptiPlex 3090 Ultra
Hardware solutions / Firmware

OptiPlex 3090
Hardware solutions / Firmware

OptiPlex 3080
Hardware solutions / Firmware

OptiPlex 3050 All-In-One
Hardware solutions / Firmware

OptiPlex 3050
Hardware solutions / Firmware

OptiPlex 3000 Thin Client
Hardware solutions / Firmware

OptiPlex 3000
Hardware solutions / Firmware

Latitude Rugged 7220EX
Hardware solutions / Firmware

Latitude 9440 2-in-1
Hardware solutions / Firmware

Latitude 7424 Rugged Extreme
Hardware solutions / Firmware

Latitude 7340
Hardware solutions / Firmware

Latitude 7330 Rugged Laptop
Hardware solutions / Firmware

Latitude 7230 Rugged Extreme
Hardware solutions / Firmware

Latitude 7220 Rugged Extreme
Hardware solutions / Firmware

Latitude 7030 Rugged Extreme
Hardware solutions / Firmware

Latitude 5540
Hardware solutions / Firmware

Latitude 5430 Rugged Laptop
Hardware solutions / Firmware

Latitude 5424 Rugged
Hardware solutions / Firmware

Latitude 5420 Rugged
Hardware solutions / Firmware

Latitude 5340
Hardware solutions / Firmware

Latitude 5310 2-IN-1
Hardware solutions / Firmware

Latitude 5310
Hardware solutions / Firmware

Latitude 5300 2-IN-1
Hardware solutions / Firmware

Latitude 5300
Hardware solutions / Firmware

Latitude 3540
Hardware solutions / Firmware

Latitude 3440
Hardware solutions / Firmware

Latitude 3390 2-in-1
Hardware solutions / Firmware

Latitude 3340
Hardware solutions / Firmware

Latitude 3310 2-in-1
Hardware solutions / Firmware

Latitude 3310
Hardware solutions / Firmware

Latitude 3300
Hardware solutions / Firmware

Inspiron 3891
Hardware solutions / Firmware

Inspiron 15 3530
Hardware solutions / Firmware

Inspiron 15 3520
Hardware solutions / Firmware

Precision 7920 Tower
Hardware solutions / Firmware

Precision 7820 Tower
Hardware solutions / Firmware

Precision 5820 Tower
Hardware solutions / Firmware

Precision 3630 Tower
Hardware solutions / Firmware

Dell G5 5090
Hardware solutions / Firmware

Alienware x17 R2
Hardware solutions / Firmware

Alienware x17 R1
Hardware solutions / Firmware

Alienware x16 R1
Hardware solutions / Firmware

Alienware x15 R2
Hardware solutions / Firmware

Alienware x15 R1
Hardware solutions / Firmware

Alienware x14 R2
Hardware solutions / Firmware

Alienware x14
Hardware solutions / Firmware

Alienware m17 R4
Hardware solutions / Firmware

Alienware m17 R3
Hardware solutions / Firmware

Alienware m15 R4
Hardware solutions / Firmware

Alienware m15 R3
Hardware solutions / Firmware

Alienware Area 51m R2
Hardware solutions / Firmware

Precision 3240 Compact
Hardware solutions / Other hardware appliances

OptiPlex 7071
Hardware solutions / Other hardware appliances

Vendor Dell

Security Bulletin

This security bulletin contains information about 4 vulnerabilities.

1) Cryptographic issues

EUVDB-ID: #VU82349

Risk: Low

CVSSv3.1: 3.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-5363

CWE-ID: CWE-310 - Cryptographic Issues

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error when processing key and initialisation vector lengths in EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() and EVP_CipherInit_ex2() function. A remote attacker can gain access to potentially sensitive information.

The following ciphers and cipher modes are impacted: RC2, RC4, RC5, CCM, GCM and OCB.

Mitigation

Install update from vendor's website.

Vulnerable software versions

XPS 13 Plus 9320: before 2413.5.68.0

XPS 13 9315: before 2413.5.68.0

Vostro 5890: before 2413.5.68.0

Vostro 5880: before 2413.5.68.0

Vostro 5090: before 2413.5.68.0

Vostro 3890: before 2413.5.68.0

Vostro 15 3530: before 2413.5.68.0

Vostro 15 3520: before 2413.5.68.0

Vostro 14 3430: before 2413.5.68.0

Vostro 14 3420: before 2413.5.68.0

Precision 3930 Rack: before 2413.5.68.0

Precision 3680 Tower: before 2413.5.68.0

Precision 3660: before 2413.5.68.0

Precision 3650 Tower: before 2413.5.68.0

Precision 3640: before 2413.5.68.0

Precision 3620 Tower: before 2413.5.68.0

Precision 3581: before 2413.5.68.0

Precision 3580: before 2413.5.68.0

Precision 3460 Small Form Factor: before 2413.5.68.0

Precision 3460 XE Small Form Factor: before 2413.5.68.0

Precision 3450: before 2413.5.68.0

Precision 3420 Tower: before 2413.5.68.0

Precision 3280 CFF: before 2413.5.68.0

Precision 3260 Compact: before 2413.5.68.0

Precision 3260 XE Compact: before 2413.5.68.0

Precision 3240 Compact: before 2413.5.68.0

OptiPlex XE4 Tower: before 2413.5.68.0

OptiPlex XE4 SFF: before 2413.5.68.0

OptiPlex Tower 7020: before 2413.5.68.0

OptiPlex Tower Plus 7010: before 2413.5.68.0

OptiPlex Tower 7010: before 2413.5.68.0

OptiPlex Small Form Factor Plus 7010: before 2413.5.68.0

OptiPlex Small Form Factor 7010: before 2413.5.68.0

OptiPlex SFF 7020: before 2413.5.68.0

OptiPlex Micro 7020: before 2413.5.68.0

OptiPlex Micro Plus 7010: before 2413.5.68.0

OptiPlex Micro 7010: before 2413.5.68.0

OptiPlex All-in-One 7410: before 2413.5.68.0

OptiPlex AIO 7420: before 2413.5.68.0

OptiPlex 7780 All-in-One: before 2413.5.68.0

OptiPlex 7770 All-In-One: before 2413.5.68.0

OptiPlex 7760 All-In-One: before 2413.5.68.0

OptiPlex 7490 All-in-One: before 2413.5.68.0

OptiPlex 7480 All-in-One: before 2413.5.68.0

OptiPlex 7470 All-In-One: before 2413.5.68.0

OptiPlex 7460 All In One: before 2413.5.68.0

OptiPlex 7450 All-In-One: before 2413.5.68.0

OptiPlex 7400 All-In-One: before 2413.5.68.0

Optiplex 7090 Ultra: before 2413.5.68.0

OptiPlex 7090 Tower: before 2413.5.68.0

OptiPlex 7071: before 2413.5.68.0

OptiPlex 7000: before 2413.5.68.0

OptiPlex 5490 All-In-One: before 2413.5.68.0

OptiPlex 5480 All-In-One: before 2413.5.68.0

OptiPlex 5400 All-In-One: before 2413.5.68.0

OptiPlex 5270 All-In-One: before 2413.5.68.0

OptiPlex 5260 All-In-One: before 2413.5.68.0

OptiPlex 5090: before 2413.5.68.0

OptiPlex 5080: before 2413.5.68.0

OptiPlex 5050: before 2435.6.35.0

OptiPlex 5000: before 2413.5.68.0

OptiPlex 3280 All-in-One: before 2413.5.68.0

OptiPlex 3090 Ultra: before 2413.5.68.0

OptiPlex 3090: before 2413.5.68.0

OptiPlex 3080: before 2413.5.68.0

OptiPlex 3050 All-In-One: before 2413.5.68.0

OptiPlex 3050: before 2435.6.35.0

OptiPlex 3000 Thin Client: before 2413.5.68.0

OptiPlex 3000: before 2413.5.68.0

Latitude Rugged 7220EX: before 2413.5.68.0

Latitude 9440 2-in-1: before 2413.5.68.0

Latitude 7424 Rugged Extreme: before 2413.5.68.0

Latitude 7340: before 2413.5.68.0

Latitude 7330 Rugged Laptop: before 2413.5.68.0

Latitude 7230 Rugged Extreme: before 2413.5.68.0

Latitude 7220 Rugged Extreme: before 2413.5.68.0

Latitude 7030 Rugged Extreme: before 2413.5.68.0

Latitude 5540: before 2413.5.68.0

Latitude 5430 Rugged Laptop: before 2413.5.68.0

Latitude 5424 Rugged: before 2413.5.68.0

Latitude 5420 Rugged: before 2413.5.68.0

Latitude 5340: before 2413.5.68.0

Latitude 5310 2-IN-1: before 2413.5.68.0

Latitude 5310: before 2413.5.68.0

Latitude 5300 2-IN-1: before 2413.5.68.0

Latitude 5300: before 2413.5.68.0

Latitude 3540: before 2413.5.68.0

Latitude 3440: before 2413.5.68.0

Latitude 3390 2-in-1: before 2435.6.35.0

Latitude 3340: before 2413.5.68.0

Latitude 3310 2-in-1: before 2413.5.68.0

Latitude 3310: before 2413.5.68.0

Latitude 3300: before 2435.6.35.0

Inspiron 3891: before 2413.5.68.0

Inspiron 15 3530: before 2413.5.68.0

Inspiron 15 3520: before 2413.5.68.0

Precision 7920 Tower: before 2413.5.68.0

Precision 7820 Tower: before 2413.5.68.0

Precision 5820 Tower: before 2413.5.68.0

Precision 3630 Tower: before 2413.5.68.0

Dell G5 5090: before 2413.5.68.0

Alienware x17 R2: before 2413.5.68.0

Alienware x17 R1: before 2413.5.68.0

Alienware x16 R1: before 2413.5.68.0

Alienware x15 R2: before 2413.5.68.0

Alienware x15 R1: before 2413.5.68.0

Alienware x14 R2: before 2413.5.68.0

Alienware x14: before 2413.5.68.0

Alienware m17 R4: before 2413.5.68.0

Alienware m17 R3: before 2413.5.68.0

Alienware m15 R4: before 2413.5.68.0

Alienware m15 R3: before 2413.5.68.0

Alienware Area 51m R2: before 2413.5.68.0

CPE2.3
External links

http://www.dell.com/support/kbdoc/nl-nl/000226215/dsa-2024-281-security-update-for-dell-client-platform-for-multiple-openssl-vulnerabilities


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Resource management error

EUVDB-ID: #VU82894

Risk: Medium

CVSSv3.1: 5.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-5678

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within DH_generate_key() and DH_check_pub_key() functions. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

XPS 13 Plus 9320: before 2413.5.68.0

XPS 13 9315: before 2413.5.68.0

Vostro 5890: before 2413.5.68.0

Vostro 5880: before 2413.5.68.0

Vostro 5090: before 2413.5.68.0

Vostro 3890: before 2413.5.68.0

Vostro 15 3530: before 2413.5.68.0

Vostro 15 3520: before 2413.5.68.0

Vostro 14 3430: before 2413.5.68.0

Vostro 14 3420: before 2413.5.68.0

Precision 3930 Rack: before 2413.5.68.0

Precision 3680 Tower: before 2413.5.68.0

Precision 3660: before 2413.5.68.0

Precision 3650 Tower: before 2413.5.68.0

Precision 3640: before 2413.5.68.0

Precision 3620 Tower: before 2413.5.68.0

Precision 3581: before 2413.5.68.0

Precision 3580: before 2413.5.68.0

Precision 3460 Small Form Factor: before 2413.5.68.0

Precision 3460 XE Small Form Factor: before 2413.5.68.0

Precision 3450: before 2413.5.68.0

Precision 3420 Tower: before 2413.5.68.0

Precision 3280 CFF: before 2413.5.68.0

Precision 3260 Compact: before 2413.5.68.0

Precision 3260 XE Compact: before 2413.5.68.0

Precision 3240 Compact: before 2413.5.68.0

OptiPlex XE4 Tower: before 2413.5.68.0

OptiPlex XE4 SFF: before 2413.5.68.0

OptiPlex Tower 7020: before 2413.5.68.0

OptiPlex Tower Plus 7010: before 2413.5.68.0

OptiPlex Tower 7010: before 2413.5.68.0

OptiPlex Small Form Factor Plus 7010: before 2413.5.68.0

OptiPlex Small Form Factor 7010: before 2413.5.68.0

OptiPlex SFF 7020: before 2413.5.68.0

OptiPlex Micro 7020: before 2413.5.68.0

OptiPlex Micro Plus 7010: before 2413.5.68.0

OptiPlex Micro 7010: before 2413.5.68.0

OptiPlex All-in-One 7410: before 2413.5.68.0

OptiPlex AIO 7420: before 2413.5.68.0

OptiPlex 7780 All-in-One: before 2413.5.68.0

OptiPlex 7770 All-In-One: before 2413.5.68.0

OptiPlex 7760 All-In-One: before 2413.5.68.0

OptiPlex 7490 All-in-One: before 2413.5.68.0

OptiPlex 7480 All-in-One: before 2413.5.68.0

OptiPlex 7470 All-In-One: before 2413.5.68.0

OptiPlex 7460 All In One: before 2413.5.68.0

OptiPlex 7450 All-In-One: before 2413.5.68.0

OptiPlex 7400 All-In-One: before 2413.5.68.0

Optiplex 7090 Ultra: before 2413.5.68.0

OptiPlex 7090 Tower: before 2413.5.68.0

OptiPlex 7071: before 2413.5.68.0

OptiPlex 7000: before 2413.5.68.0

OptiPlex 5490 All-In-One: before 2413.5.68.0

OptiPlex 5480 All-In-One: before 2413.5.68.0

OptiPlex 5400 All-In-One: before 2413.5.68.0

OptiPlex 5270 All-In-One: before 2413.5.68.0

OptiPlex 5260 All-In-One: before 2413.5.68.0

OptiPlex 5090: before 2413.5.68.0

OptiPlex 5080: before 2413.5.68.0

OptiPlex 5050: before 2435.6.35.0

OptiPlex 5000: before 2413.5.68.0

OptiPlex 3280 All-in-One: before 2413.5.68.0

OptiPlex 3090 Ultra: before 2413.5.68.0

OptiPlex 3090: before 2413.5.68.0

OptiPlex 3080: before 2413.5.68.0

OptiPlex 3050 All-In-One: before 2413.5.68.0

OptiPlex 3050: before 2435.6.35.0

OptiPlex 3000 Thin Client: before 2413.5.68.0

OptiPlex 3000: before 2413.5.68.0

Latitude Rugged 7220EX: before 2413.5.68.0

Latitude 9440 2-in-1: before 2413.5.68.0

Latitude 7424 Rugged Extreme: before 2413.5.68.0

Latitude 7340: before 2413.5.68.0

Latitude 7330 Rugged Laptop: before 2413.5.68.0

Latitude 7230 Rugged Extreme: before 2413.5.68.0

Latitude 7220 Rugged Extreme: before 2413.5.68.0

Latitude 7030 Rugged Extreme: before 2413.5.68.0

Latitude 5540: before 2413.5.68.0

Latitude 5430 Rugged Laptop: before 2413.5.68.0

Latitude 5424 Rugged: before 2413.5.68.0

Latitude 5420 Rugged: before 2413.5.68.0

Latitude 5340: before 2413.5.68.0

Latitude 5310 2-IN-1: before 2413.5.68.0

Latitude 5310: before 2413.5.68.0

Latitude 5300 2-IN-1: before 2413.5.68.0

Latitude 5300: before 2413.5.68.0

Latitude 3540: before 2413.5.68.0

Latitude 3440: before 2413.5.68.0

Latitude 3390 2-in-1: before 2435.6.35.0

Latitude 3340: before 2413.5.68.0

Latitude 3310 2-in-1: before 2413.5.68.0

Latitude 3310: before 2413.5.68.0

Latitude 3300: before 2435.6.35.0

Inspiron 3891: before 2413.5.68.0

Inspiron 15 3530: before 2413.5.68.0

Inspiron 15 3520: before 2413.5.68.0

Precision 7920 Tower: before 2413.5.68.0

Precision 7820 Tower: before 2413.5.68.0

Precision 5820 Tower: before 2413.5.68.0

Precision 3630 Tower: before 2413.5.68.0

Dell G5 5090: before 2413.5.68.0

Alienware x17 R2: before 2413.5.68.0

Alienware x17 R1: before 2413.5.68.0

Alienware x16 R1: before 2413.5.68.0

Alienware x15 R2: before 2413.5.68.0

Alienware x15 R1: before 2413.5.68.0

Alienware x14 R2: before 2413.5.68.0

Alienware x14: before 2413.5.68.0

Alienware m17 R4: before 2413.5.68.0

Alienware m17 R3: before 2413.5.68.0

Alienware m15 R4: before 2413.5.68.0

Alienware m15 R3: before 2413.5.68.0

Alienware Area 51m R2: before 2413.5.68.0

CPE2.3
External links

http://www.dell.com/support/kbdoc/nl-nl/000226215/dsa-2024-281-security-update-for-dell-client-platform-for-multiple-openssl-vulnerabilities


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Resource management error

EUVDB-ID: #VU85399

Risk: Low

CVSSv3.1: 3.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-6237

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the way the EVP_PKEY_public_check() function handles RSA public keys. A remote attacker can supply an RSA key obtained from an untrusted source and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

XPS 13 Plus 9320: before 2413.5.68.0

XPS 13 9315: before 2413.5.68.0

Vostro 5890: before 2413.5.68.0

Vostro 5880: before 2413.5.68.0

Vostro 5090: before 2413.5.68.0

Vostro 3890: before 2413.5.68.0

Vostro 15 3530: before 2413.5.68.0

Vostro 15 3520: before 2413.5.68.0

Vostro 14 3430: before 2413.5.68.0

Vostro 14 3420: before 2413.5.68.0

Precision 3930 Rack: before 2413.5.68.0

Precision 3680 Tower: before 2413.5.68.0

Precision 3660: before 2413.5.68.0

Precision 3650 Tower: before 2413.5.68.0

Precision 3640: before 2413.5.68.0

Precision 3620 Tower: before 2413.5.68.0

Precision 3581: before 2413.5.68.0

Precision 3580: before 2413.5.68.0

Precision 3460 Small Form Factor: before 2413.5.68.0

Precision 3460 XE Small Form Factor: before 2413.5.68.0

Precision 3450: before 2413.5.68.0

Precision 3420 Tower: before 2413.5.68.0

Precision 3280 CFF: before 2413.5.68.0

Precision 3260 Compact: before 2413.5.68.0

Precision 3260 XE Compact: before 2413.5.68.0

Precision 3240 Compact: before 2413.5.68.0

OptiPlex XE4 Tower: before 2413.5.68.0

OptiPlex XE4 SFF: before 2413.5.68.0

OptiPlex Tower 7020: before 2413.5.68.0

OptiPlex Tower Plus 7010: before 2413.5.68.0

OptiPlex Tower 7010: before 2413.5.68.0

OptiPlex Small Form Factor Plus 7010: before 2413.5.68.0

OptiPlex Small Form Factor 7010: before 2413.5.68.0

OptiPlex SFF 7020: before 2413.5.68.0

OptiPlex Micro 7020: before 2413.5.68.0

OptiPlex Micro Plus 7010: before 2413.5.68.0

OptiPlex Micro 7010: before 2413.5.68.0

OptiPlex All-in-One 7410: before 2413.5.68.0

OptiPlex AIO 7420: before 2413.5.68.0

OptiPlex 7780 All-in-One: before 2413.5.68.0

OptiPlex 7770 All-In-One: before 2413.5.68.0

OptiPlex 7760 All-In-One: before 2413.5.68.0

OptiPlex 7490 All-in-One: before 2413.5.68.0

OptiPlex 7480 All-in-One: before 2413.5.68.0

OptiPlex 7470 All-In-One: before 2413.5.68.0

OptiPlex 7460 All In One: before 2413.5.68.0

OptiPlex 7450 All-In-One: before 2413.5.68.0

OptiPlex 7400 All-In-One: before 2413.5.68.0

Optiplex 7090 Ultra: before 2413.5.68.0

OptiPlex 7090 Tower: before 2413.5.68.0

OptiPlex 7071: before 2413.5.68.0

OptiPlex 7000: before 2413.5.68.0

OptiPlex 5490 All-In-One: before 2413.5.68.0

OptiPlex 5480 All-In-One: before 2413.5.68.0

OptiPlex 5400 All-In-One: before 2413.5.68.0

OptiPlex 5270 All-In-One: before 2413.5.68.0

OptiPlex 5260 All-In-One: before 2413.5.68.0

OptiPlex 5090: before 2413.5.68.0

OptiPlex 5080: before 2413.5.68.0

OptiPlex 5050: before 2435.6.35.0

OptiPlex 5000: before 2413.5.68.0

OptiPlex 3280 All-in-One: before 2413.5.68.0

OptiPlex 3090 Ultra: before 2413.5.68.0

OptiPlex 3090: before 2413.5.68.0

OptiPlex 3080: before 2413.5.68.0

OptiPlex 3050 All-In-One: before 2413.5.68.0

OptiPlex 3050: before 2435.6.35.0

OptiPlex 3000 Thin Client: before 2413.5.68.0

OptiPlex 3000: before 2413.5.68.0

Latitude Rugged 7220EX: before 2413.5.68.0

Latitude 9440 2-in-1: before 2413.5.68.0

Latitude 7424 Rugged Extreme: before 2413.5.68.0

Latitude 7340: before 2413.5.68.0

Latitude 7330 Rugged Laptop: before 2413.5.68.0

Latitude 7230 Rugged Extreme: before 2413.5.68.0

Latitude 7220 Rugged Extreme: before 2413.5.68.0

Latitude 7030 Rugged Extreme: before 2413.5.68.0

Latitude 5540: before 2413.5.68.0

Latitude 5430 Rugged Laptop: before 2413.5.68.0

Latitude 5424 Rugged: before 2413.5.68.0

Latitude 5420 Rugged: before 2413.5.68.0

Latitude 5340: before 2413.5.68.0

Latitude 5310 2-IN-1: before 2413.5.68.0

Latitude 5310: before 2413.5.68.0

Latitude 5300 2-IN-1: before 2413.5.68.0

Latitude 5300: before 2413.5.68.0

Latitude 3540: before 2413.5.68.0

Latitude 3440: before 2413.5.68.0

Latitude 3390 2-in-1: before 2435.6.35.0

Latitude 3340: before 2413.5.68.0

Latitude 3310 2-in-1: before 2413.5.68.0

Latitude 3310: before 2413.5.68.0

Latitude 3300: before 2435.6.35.0

Inspiron 3891: before 2413.5.68.0

Inspiron 15 3530: before 2413.5.68.0

Inspiron 15 3520: before 2413.5.68.0

Precision 7920 Tower: before 2413.5.68.0

Precision 7820 Tower: before 2413.5.68.0

Precision 5820 Tower: before 2413.5.68.0

Precision 3630 Tower: before 2413.5.68.0

Dell G5 5090: before 2413.5.68.0

Alienware x17 R2: before 2413.5.68.0

Alienware x17 R1: before 2413.5.68.0

Alienware x16 R1: before 2413.5.68.0

Alienware x15 R2: before 2413.5.68.0

Alienware x15 R1: before 2413.5.68.0

Alienware x14 R2: before 2413.5.68.0

Alienware x14: before 2413.5.68.0

Alienware m17 R4: before 2413.5.68.0

Alienware m17 R3: before 2413.5.68.0

Alienware m15 R4: before 2413.5.68.0

Alienware m15 R3: before 2413.5.68.0

Alienware Area 51m R2: before 2413.5.68.0

CPE2.3
External links

http://www.dell.com/support/kbdoc/nl-nl/000226215/dsa-2024-281-security-update-for-dell-client-platform-for-multiple-openssl-vulnerabilities


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) NULL pointer dereference

EUVDB-ID: #VU85808

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-0727

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error when processing fields in the PKCS12 certificate. A remote attacker can pass specially crafted certificate to the server and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

XPS 13 Plus 9320: before 2413.5.68.0

XPS 13 9315: before 2413.5.68.0

Vostro 5890: before 2413.5.68.0

Vostro 5880: before 2413.5.68.0

Vostro 5090: before 2413.5.68.0

Vostro 3890: before 2413.5.68.0

Vostro 15 3530: before 2413.5.68.0

Vostro 15 3520: before 2413.5.68.0

Vostro 14 3430: before 2413.5.68.0

Vostro 14 3420: before 2413.5.68.0

Precision 3930 Rack: before 2413.5.68.0

Precision 3680 Tower: before 2413.5.68.0

Precision 3660: before 2413.5.68.0

Precision 3650 Tower: before 2413.5.68.0

Precision 3640: before 2413.5.68.0

Precision 3620 Tower: before 2413.5.68.0

Precision 3581: before 2413.5.68.0

Precision 3580: before 2413.5.68.0

Precision 3460 Small Form Factor: before 2413.5.68.0

Precision 3460 XE Small Form Factor: before 2413.5.68.0

Precision 3450: before 2413.5.68.0

Precision 3420 Tower: before 2413.5.68.0

Precision 3280 CFF: before 2413.5.68.0

Precision 3260 Compact: before 2413.5.68.0

Precision 3260 XE Compact: before 2413.5.68.0

Precision 3240 Compact: before 2413.5.68.0

OptiPlex XE4 Tower: before 2413.5.68.0

OptiPlex XE4 SFF: before 2413.5.68.0

OptiPlex Tower 7020: before 2413.5.68.0

OptiPlex Tower Plus 7010: before 2413.5.68.0

OptiPlex Tower 7010: before 2413.5.68.0

OptiPlex Small Form Factor Plus 7010: before 2413.5.68.0

OptiPlex Small Form Factor 7010: before 2413.5.68.0

OptiPlex SFF 7020: before 2413.5.68.0

OptiPlex Micro 7020: before 2413.5.68.0

OptiPlex Micro Plus 7010: before 2413.5.68.0

OptiPlex Micro 7010: before 2413.5.68.0

OptiPlex All-in-One 7410: before 2413.5.68.0

OptiPlex AIO 7420: before 2413.5.68.0

OptiPlex 7780 All-in-One: before 2413.5.68.0

OptiPlex 7770 All-In-One: before 2413.5.68.0

OptiPlex 7760 All-In-One: before 2413.5.68.0

OptiPlex 7490 All-in-One: before 2413.5.68.0

OptiPlex 7480 All-in-One: before 2413.5.68.0

OptiPlex 7470 All-In-One: before 2413.5.68.0

OptiPlex 7460 All In One: before 2413.5.68.0

OptiPlex 7450 All-In-One: before 2413.5.68.0

OptiPlex 7400 All-In-One: before 2413.5.68.0

Optiplex 7090 Ultra: before 2413.5.68.0

OptiPlex 7090 Tower: before 2413.5.68.0

OptiPlex 7071: before 2413.5.68.0

OptiPlex 7000: before 2413.5.68.0

OptiPlex 5490 All-In-One: before 2413.5.68.0

OptiPlex 5480 All-In-One: before 2413.5.68.0

OptiPlex 5400 All-In-One: before 2413.5.68.0

OptiPlex 5270 All-In-One: before 2413.5.68.0

OptiPlex 5260 All-In-One: before 2413.5.68.0

OptiPlex 5090: before 2413.5.68.0

OptiPlex 5080: before 2413.5.68.0

OptiPlex 5050: before 2435.6.35.0

OptiPlex 5000: before 2413.5.68.0

OptiPlex 3280 All-in-One: before 2413.5.68.0

OptiPlex 3090 Ultra: before 2413.5.68.0

OptiPlex 3090: before 2413.5.68.0

OptiPlex 3080: before 2413.5.68.0

OptiPlex 3050 All-In-One: before 2413.5.68.0

OptiPlex 3050: before 2435.6.35.0

OptiPlex 3000 Thin Client: before 2413.5.68.0

OptiPlex 3000: before 2413.5.68.0

Latitude Rugged 7220EX: before 2413.5.68.0

Latitude 9440 2-in-1: before 2413.5.68.0

Latitude 7424 Rugged Extreme: before 2413.5.68.0

Latitude 7340: before 2413.5.68.0

Latitude 7330 Rugged Laptop: before 2413.5.68.0

Latitude 7230 Rugged Extreme: before 2413.5.68.0

Latitude 7220 Rugged Extreme: before 2413.5.68.0

Latitude 7030 Rugged Extreme: before 2413.5.68.0

Latitude 5540: before 2413.5.68.0

Latitude 5430 Rugged Laptop: before 2413.5.68.0

Latitude 5424 Rugged: before 2413.5.68.0

Latitude 5420 Rugged: before 2413.5.68.0

Latitude 5340: before 2413.5.68.0

Latitude 5310 2-IN-1: before 2413.5.68.0

Latitude 5310: before 2413.5.68.0

Latitude 5300 2-IN-1: before 2413.5.68.0

Latitude 5300: before 2413.5.68.0

Latitude 3540: before 2413.5.68.0

Latitude 3440: before 2413.5.68.0

Latitude 3390 2-in-1: before 2435.6.35.0

Latitude 3340: before 2413.5.68.0

Latitude 3310 2-in-1: before 2413.5.68.0

Latitude 3310: before 2413.5.68.0

Latitude 3300: before 2435.6.35.0

Inspiron 3891: before 2413.5.68.0

Inspiron 15 3530: before 2413.5.68.0

Inspiron 15 3520: before 2413.5.68.0

Precision 7920 Tower: before 2413.5.68.0

Precision 7820 Tower: before 2413.5.68.0

Precision 5820 Tower: before 2413.5.68.0

Precision 3630 Tower: before 2413.5.68.0

Dell G5 5090: before 2413.5.68.0

Alienware x17 R2: before 2413.5.68.0

Alienware x17 R1: before 2413.5.68.0

Alienware x16 R1: before 2413.5.68.0

Alienware x15 R2: before 2413.5.68.0

Alienware x15 R1: before 2413.5.68.0

Alienware x14 R2: before 2413.5.68.0

Alienware x14: before 2413.5.68.0

Alienware m17 R4: before 2413.5.68.0

Alienware m17 R3: before 2413.5.68.0

Alienware m15 R4: before 2413.5.68.0

Alienware m15 R3: before 2413.5.68.0

Alienware Area 51m R2: before 2413.5.68.0

CPE2.3
External links

http://www.dell.com/support/kbdoc/nl-nl/000226215/dsa-2024-281-security-update-for-dell-client-platform-for-multiple-openssl-vulnerabilities


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###