8.2
CVE-2022-24416
- EPSS 0.11%
- Veröffentlicht 11.03.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:50:22
- Quelle security_alert@emc.com
- Teams Watchlist Login
- Unerledigt Login
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Alienware 13 R3 Firmware Version < 1.16.1
Dell ≫ Alienware 15 R3 Firmware Version < 1.16.1
Dell ≫ Alienware 15 R4 Firmware Version < 1.17.0
Dell ≫ Alienware 17 R4 Firmware Version < 1.16.1
Dell ≫ Alienware 17 R5 Firmware Version < 1.17.0
Dell ≫ Alienware Area 51m R1 Firmware Version < 1.18.0
Dell ≫ Alienware Area 51m R2 Firmware Version < 1.13.0
Dell ≫ Alienware Aurora R8 Firmware Version < 1.0.20
Dell ≫ Alienware M15 R2 Firmware Version < 1.12.0
Dell ≫ Alienware M15 R3 Firmware Version < 1.14.0
Dell ≫ Alienware M15 R4 Firmware Version < 1.8.0
Dell ≫ Alienware M17 R2 Firmware Version < 1.12.0
Dell ≫ Alienware M17 R3 Firmware Version < 1.14.0
Dell ≫ Alienware M17 R4 Firmware Version < 1.8.0
Dell ≫ Alienware X15 R1 Firmware Version < 1.7.0
Dell ≫ Alienware X17 R1 Firmware Version < 1.7.0
Dell ≫ Edge Gateway 3000 Firmware Version < 1.7.0
Dell ≫ Edge Gateway 5000 Firmware Version < 1.17.0
Dell ≫ Edge Gateway 5100 Firmware Version < 1.17.0
Dell ≫ Embedded Box Pc 3000 Firmware Version < 1.13.0
Dell ≫ Embedded Box Pc 5000 Firmware Version < 1.14.0
Dell ≫ Inspiron 14 3473 Firmware Version < 1.14.0
Dell ≫ Inspiron 15 3573 Firmware Version < 1.14.0
Dell ≫ Inspiron 15 5566 Firmware Version < 1.18.0
Dell ≫ Inspiron 3277 Firmware Version < 1.19.0
Dell ≫ Inspiron 3465 Firmware Version < 1.12.0
Dell ≫ Inspiron 3477 Firmware Version < 1.19.0
Dell ≫ Inspiron 3482 Firmware Version < 1.13.0
Dell ≫ Inspiron 3502 Firmware Version < 1.7.0
Dell ≫ Inspiron 3510 Firmware Version < 1.6.0
Dell ≫ Inspiron 3565 Firmware Version < 1.12.0
Dell ≫ Inspiron 3582 Firmware Version < 1.13.0
Dell ≫ Inspiron 3782 Firmware Version < 1.13.0
Dell ≫ Latitude 3379 Firmware Version < 1.0.34
Dell ≫ Vostro 14 5468 Firmware Version < 1.19.0
Dell ≫ Vostro 15 5568 Firmware Version < 1.19.0
Dell ≫ Vostro 3267 Firmware Version < 1.20.0
Dell ≫ Vostro 3268 Firmware Version < 1.20.0
Dell ≫ Vostro 3572 Firmware Version < 1.14.0
Dell ≫ Vostro 3582 Firmware Version < 1.13.0
Dell ≫ Vostro 3660 Firmware Version < 1.20.0
Dell ≫ Vostro 3667 Firmware Version < 1.20.0
Dell ≫ Vostro 3668 Firmware Version < 1.20.0
Dell ≫ Vostro 3669 Firmware Version < 1.20.0
Dell ≫ Wyse 7040 Thin Client Firmware Version < 1.15.0
Dell ≫ Xps 8930 Firmware Version < 1.1.21
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.3 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
security_alert@emc.com | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.