CVE-2024-38296

Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:dell:intel_management_engine_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_3200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:dell:intel_management_engine_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_5200:-:*:*:*:*:*:*:*

History

04 Feb 2025, 16:05

Type Values Removed Values Added
CPE cpe:2.3:h:dell:edge_gateway_3200:-:*:*:*:*:*:*:*
cpe:2.3:a:dell:intel_management_engine_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_5200:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.4
CWE NVD-CWE-noinfo
First Time Dell intel Management Engine Firmware Update Utility
Dell
Dell edge Gateway 3200
Dell edge Gateway 5200
References () https://www.dell.com/support/kbdoc/en-us/000250949/dsa-2024-345-security-update-for-dell-networking-edge-gateway-5200-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000250949/dsa-2024-345-security-update-for-dell-networking-edge-gateway-5200-vulnerability - Vendor Advisory

09 Dec 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-22 03:15

Updated : 2025-02-04 16:05


NVD link : CVE-2024-38296

Mitre link : CVE-2024-38296


JSON object : View

Products Affected

dell

  • edge_gateway_5200
  • edge_gateway_3200
  • intel_management_engine_firmware_update_utility