6

CVE-2022-22558

Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker could potentially exploit this vulnerability leading to arbitrary writes or denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ R6415 Firmware Version < 1.18.0
   Dell ≫ R6415 Version -
Dell ≫ R7415 Firmware Version < 1.18.0
   Dell ≫ R7415 Version -
Dell ≫ R7425 Firmware Version < 1.18.0
   Dell ≫ R7425 Version -
Dell ≫ R730 Firmware Version < 2.14.0
   Dell ≫ R730 Version -
Dell ≫ R730xd Firmware Version < 2.14.0
   Dell ≫ R730xd Version -
Dell ≫ R630 Firmware Version < 2.14.0
   Dell ≫ R630 Version -
Dell ≫ C4130 Firmware Version < 2.14.0
   Dell ≫ C4130 Version -
Dell ≫ M630 Firmware Version < 2.14.0
   Dell ≫ M630 Version -
Dell ≫ M630p Firmware Version < 2.14.0
   Dell ≫ M630p Version -
Dell ≫ Fc630 Firmware Version < 2.14.0
   Dell ≫ Fc630 Version -
Dell ≫ Fc430 Firmware Version < 2.14.0
   Dell ≫ Fc430 Version -
Dell ≫ M830 Firmware Version < 2.14.0
   Dell ≫ M830 Version -
Dell ≫ M830p Firmware Version < 2.14.0
   Dell ≫ M830p Version -
Dell ≫ Fc830 Firmware Version < 2.14.0
   Dell ≫ Fc830 Version -
Dell ≫ T630 Firmware Version < 2.14.0
   Dell ≫ T630 Version -
Dell ≫ R530 Firmware Version < 2.14.0
   Dell ≫ R530 Version -
Dell ≫ R430 Firmware Version < 2.14.0
   Dell ≫ R430 Version -
Dell ≫ T430 Firmware Version < 2.14.0
   Dell ≫ T430 Version -
Dell ≫ R830 Firmware Version < 1.14.0
   Dell ≫ R830 Version -
Dell ≫ C6320 Firmware Version < 2.14.1
   Dell ≫ C6320 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.106
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6 0.8 5.2
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:N/I:P/A:P
EMC 5.7 0.5 5.2
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

https://www.dell.com/support/kbdoc/000197971
Vendor Advisory