6

CVE-2022-22558

Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker could potentially exploit this vulnerability leading to arbitrary writes or denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellR6415 Firmware Version < 1.18.0
   DellR6415 Version-
DellR7415 Firmware Version < 1.18.0
   DellR7415 Version-
DellR7425 Firmware Version < 1.18.0
   DellR7425 Version-
DellR730 Firmware Version < 2.14.0
   DellR730 Version-
DellR730xd Firmware Version < 2.14.0
   DellR730xd Version-
DellR630 Firmware Version < 2.14.0
   DellR630 Version-
DellC4130 Firmware Version < 2.14.0
   DellC4130 Version-
DellM630 Firmware Version < 2.14.0
   DellM630 Version-
DellM630p Firmware Version < 2.14.0
   DellM630p Version-
DellFc630 Firmware Version < 2.14.0
   DellFc630 Version-
DellFc430 Firmware Version < 2.14.0
   DellFc430 Version-
DellM830 Firmware Version < 2.14.0
   DellM830 Version-
DellM830p Firmware Version < 2.14.0
   DellM830p Version-
DellFc830 Firmware Version < 2.14.0
   DellFc830 Version-
DellT630 Firmware Version < 2.14.0
   DellT630 Version-
DellR530 Firmware Version < 2.14.0
   DellR530 Version-
DellR430 Firmware Version < 2.14.0
   DellR430 Version-
DellT430 Firmware Version < 2.14.0
   DellT430 Version-
DellR830 Firmware Version < 1.14.0
   DellR830 Version-
DellC6320 Firmware Version < 2.14.1
   DellC6320 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.27
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6 0.8 5.2
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
nvd@nist.gov 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:N/I:P/A:P
security_alert@emc.com 5.7 0.5 5.2
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.