Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000224763


DSA-2024-122: Security Update for Dell Client BIOS for an Incorrect Authorization Vulnerability

Summary: Dell Client BIOS remediation is available for an Incorrect Authorization Vulnerability that could be exploited by malicious users to compromise the affected system.

Article Content


Impact

Medium

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-0160 Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS. 6.8
 
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-0160 Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS. 6.8
 
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product

Software/Firmware Affected Versions Remediated Versions BIOS Release Date Link
Dell G7 7500 BIOS Versions prior to 1.32.0 Versions 1.32.0 or later 05/30/2024 Go to the Drivers & Downloads site for updates
Dell G7 7700 BIOS Versions prior to 1.32.0 Versions 1.32.0 or later 05/30/2024 Go to the Drivers & Downloads site for updates

Product

Software/Firmware Affected Versions Remediated Versions BIOS Release Date Link
Dell G7 7500 BIOS Versions prior to 1.32.0 Versions 1.32.0 or later 05/30/2024 Go to the Drivers & Downloads site for updates
Dell G7 7700 BIOS Versions prior to 1.32.0 Versions 1.32.0 or later 05/30/2024 Go to the Drivers & Downloads site for updates

Workarounds and Mitigations

None

Acknowledgements

CVE-2024-0160: Dell would like to thank Ben McEwan, Penetration Tester at Bridewell (www.bridewell.com) for reporting this issue.

Revision History

Revision DateDescription
1.02024-06-11Initial Release

Related Information


Article Properties


Affected Product

Dell G7 15 7500, Dell G7 17 7700

Last Published Date

11 Jun 2024

Article Type

Dell Security Advisory