6
CVE-2022-22558
- EPSS 0.1%
- Veröffentlicht 21.04.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:47:01
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker could potentially exploit this vulnerability leading to arbitrary writes or denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ R6415 Firmware Version < 1.18.0
Dell ≫ R7415 Firmware Version < 1.18.0
Dell ≫ R7425 Firmware Version < 1.18.0
Dell ≫ R730 Firmware Version < 2.14.0
Dell ≫ R730xd Firmware Version < 2.14.0
Dell ≫ R630 Firmware Version < 2.14.0
Dell ≫ C4130 Firmware Version < 2.14.0
Dell ≫ M630 Firmware Version < 2.14.0
Dell ≫ M630p Firmware Version < 2.14.0
Dell ≫ Fc630 Firmware Version < 2.14.0
Dell ≫ Fc430 Firmware Version < 2.14.0
Dell ≫ M830 Firmware Version < 2.14.0
Dell ≫ M830p Firmware Version < 2.14.0
Dell ≫ Fc830 Firmware Version < 2.14.0
Dell ≫ T630 Firmware Version < 2.14.0
Dell ≫ R530 Firmware Version < 2.14.0
Dell ≫ R430 Firmware Version < 2.14.0
Dell ≫ T430 Firmware Version < 2.14.0
Dell ≫ R830 Firmware Version < 1.14.0
Dell ≫ C6320 Firmware Version < 2.14.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.27 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6 | 0.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
|
| nvd@nist.gov | 3.6 | 3.9 | 4.9 |
AV:L/AC:L/Au:N/C:N/I:P/A:P
|
| security_alert@emc.com | 5.7 | 0.5 | 5.2 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.