#VU96638 Input validation error in Dell products - CVE-2024-38303 

 

#VU96638 Input validation error in Dell products - CVE-2024-38303

Published: August 30, 2024


Vulnerability identifier: #VU96638
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-38303
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
PowerEdge R740
PowerEdge R740XD
PowerEdge R640
PowerEdge R940
PowerEdge R540
PowerEdge R440
PowerEdge T440
PowerEdge XR2
PowerEdge R740XD2
PowerEdge R840
PowerEdge R940XA
PowerEdge T640
PowerEdge C6420
PowerEdge FC640
PowerEdge M640
PowerEdge M640 (for PE VRTX)
PowerEdge MX740C
PowerEdge MX840C
PowerEdge C4140
DSS 8440
PowerEdge XE2420
PowerEdge XE7420
PowerEdge XE7440
Dell EMC Storage NX3240
Dell EMC Storage NX3340
Dell EMC XC Core 6420 System
Dell EMC XC Core XC640 System
Dell EMC XC Core XC740xd System
Dell EMC XC Core XC740xd2
Dell EMC XC Core XC940 System
Dell EMC XC Core XCXR2
Software vendor:
Dell

Description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied input. A local user can gain access to sensitive information.


Remediation

Install updates from vendor's website.

External links