8.2

CVE-2022-24419

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.

Data is provided by the National Vulnerability Database (NVD)
DellAlienware 13 R3 Firmware Version < 1.16.1
   DellAlienware 13 R3 Version-
DellAlienware 15 R3 Firmware Version < 1.16.1
   DellAlienware 15 R3 Version-
DellAlienware 15 R4 Firmware Version < 1.17.0
   DellAlienware 15 R4 Version-
DellAlienware 17 R4 Firmware Version < 1.16.1
   DellAlienware 17 R4 Version-
DellAlienware 17 R5 Firmware Version < 1.17.0
   DellAlienware 17 R5 Version-
DellAlienware Area 51m R1 Firmware Version < 1.18.0
   DellAlienware Area 51m R1 Version-
DellAlienware Area 51m R2 Firmware Version < 1.13.0
   DellAlienware Area 51m R2 Version-
DellAlienware Aurora R8 Firmware Version < 1.0.20
   DellAlienware Aurora R8 Version-
DellAlienware M15 R2 Firmware Version < 1.12.0
   DellAlienware M15 R2 Version-
DellAlienware M15 R3 Firmware Version < 1.14.0
   DellAlienware M15 R3 Version-
DellAlienware M15 R4 Firmware Version < 1.8.0
   DellAlienware M15 R4 Version-
DellAlienware M17 R2 Firmware Version < 1.12.0
   DellAlienware M17 R2 Version-
DellAlienware M17 R3 Firmware Version < 1.14.0
   DellAlienware M17 R3 Version-
DellAlienware M17 R4 Firmware Version < 1.8.0
   DellAlienware M17 R4 Version-
DellAlienware X15 R1 Firmware Version < 1.7.0
   DellAlienware X15 R1 Version-
DellAlienware X17 R1 Firmware Version < 1.7.0
   DellAlienware X17 R1 Version-
DellEdge Gateway 3000 Firmware Version < 1.7.0
   DellEdge Gateway 3000 Version-
DellEdge Gateway 5000 Firmware Version < 1.17.0
   DellEdge Gateway 5000 Version-
DellEdge Gateway 5100 Firmware Version < 1.17.0
   DellEdge Gateway 5100 Version-
DellEmbedded Box Pc 3000 Firmware Version < 1.13.0
   DellEmbedded Box Pc 3000 Version-
DellEmbedded Box Pc 5000 Firmware Version < 1.14.0
   DellEmbedded Box Pc 5000 Version-
DellInspiron 14 3473 Firmware Version < 1.14.0
   DellInspiron 14 3473 Version-
DellInspiron 15 3573 Firmware Version < 1.14.0
   DellInspiron 15 3573 Version-
DellInspiron 15 5566 Firmware Version < 1.18.0
   DellInspiron 15 5566 Version-
DellInspiron 3277 Firmware Version < 1.19.0
   DellInspiron 3277 Version-
DellInspiron 3465 Firmware Version < 1.12.0
   DellInspiron 3465 Version-
DellInspiron 3477 Firmware Version < 1.19.0
   DellInspiron 3477 Version-
DellInspiron 3482 Firmware Version < 1.13.0
   DellInspiron 3482 Version-
DellInspiron 3502 Firmware Version < 1.7.0
   DellInspiron 3502 Version-
DellInspiron 3510 Firmware Version < 1.6.0
   DellInspiron 3510 Version-
DellInspiron 3565 Firmware Version < 1.12.0
   DellInspiron 3565 Version-
DellInspiron 3582 Firmware Version < 1.13.0
   DellInspiron 3582 Version-
DellInspiron 3782 Firmware Version < 1.13.0
   DellInspiron 3782 Version-
DellLatitude 3379 Firmware Version < 1.0.34
   DellLatitude 3379 Version-
DellVostro 14 5468 Firmware Version < 1.19.0
   DellVostro 14 5468 Version-
DellVostro 15 5568 Firmware Version < 1.19.0
   DellVostro 15 5568 Version-
DellVostro 3267 Firmware Version < 1.20.0
   DellVostro 3267 Version-
DellVostro 3268 Firmware Version < 1.20.0
   DellVostro 3268 Version-
DellVostro 3572 Firmware Version < 1.14.0
   DellVostro 3572 Version-
DellVostro 3582 Firmware Version < 1.13.0
   DellVostro 3582 Version-
DellVostro 3660 Firmware Version < 1.20.0
   DellVostro 3660 Version-
DellVostro 3667 Firmware Version < 1.20.0
   DellVostro 3667 Version-
DellVostro 3668 Firmware Version < 1.20.0
   DellVostro 3668 Version-
DellVostro 3669 Firmware Version < 1.20.0
   DellVostro 3669 Version-
DellWyse 7040 Thin Client Firmware Version < 1.15.0
   DellWyse 7040 Thin Client Version-
DellXps 8930 Firmware Version < 1.1.21
   DellXps 8930 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.113
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
security_alert@emc.com 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.