CVE-2024-38798

Source
https://cve.org/CVERecord?id=CVE-2024-38798
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38798.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-38798
Aliases
  • GHSA-q2c6-37h5-7cwf
Downstream
Published
2025-12-09T16:17:27.787Z
Modified
2026-03-12T05:48:42.132439Z
Severity
  • 5.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to

possible information disclosure or escalation of privilege

and impact Confidentiality.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38798.json"