CVE-2024-38296

Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:dell:intel_management_engine_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_3200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:dell:intel_management_engine_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_5200:-:*:*:*:*:*:*:*

History

04 Feb 2025, 16:05

Type Values Removed Values Added
CPE cpe:2.3:h:dell:edge_gateway_3200:-:*:*:*:*:*:*:*
cpe:2.3:a:dell:intel_management_engine_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_5200:-:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Dell edge Gateway 5200
Dell intel Management Engine Firmware Update Utility
Dell edge Gateway 3200
Dell
References () https://www.dell.com/support/kbdoc/en-us/000250949/dsa-2024-345-security-update-for-dell-networking-edge-gateway-5200-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000250949/dsa-2024-345-security-update-for-dell-networking-edge-gateway-5200-vulnerability - Vendor Advisory

09 Dec 2024, 15:15

Type Values Removed Values Added
Summary
  • (es) Dell Edge Gateway 5200 (Coffee Lake S), versiones anteriores a 12.0.94.2380, contiene una vulnerabilidad de exposición de información confidencial en estructuras microarquitectónicas compartidas durante la ejecución transitoria. Un atacante con privilegios elevados y acceso local podría aprovechar esta vulnerabilidad, lo que provocaría la exposición de información.
Summary (en) Dell Edge Gateway 5200 (Coffee Lake S), versions prior to 12.0.94.2380, contains an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. (en) Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.

22 Nov 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-22 03:15

Updated : 2025-02-04 16:05


NVD link : CVE-2024-38296

Mitre link : CVE-2024-38296

CVE.ORG link : CVE-2024-38296


JSON object : View

Products Affected

dell

  • intel_management_engine_firmware_update_utility
  • edge_gateway_3200
  • edge_gateway_5200