CVE-2024-32860 is an improper input validation vulnerability in an externally developed component of Dell Client Platform BIOS. This high-severity flaw (CVSS 8.2) allows a high-privileged attacker with local access to execute arbitrary code, potentially leading to full system compromise. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's minimal community discussion, the potential impact remains significant for affected Dell platforms. Dell users should apply vendor-provided patches promptly to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.26.0CPE matchmatch criteria | cpe:2.3:o:dell:alienware_area_51m_r2_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.24CPE matchmatch criteria | cpe:2.3:o:dell:alienware_aurora_r11_firmware:*:*:*:*:*:*:*:* | ||
< 1.1.25CPE matchmatch criteria | cpe:2.3:o:dell:alienware_aurora_r12_firmware:*:*:*:*:*:*:*:* | ||
<= 1.1.19CPE matchmatch criteria | cpe:2.3:o:dell:alienware_aurora_r13_firmware:*:*:*:*:*:*:*:* | ||
< 1.1.12CPE matchmatch criteria | cpe:2.3:o:dell:alienware_aurora_r15_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.