7.8

CVE-2022-26862

Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.

Data is provided by the National Vulnerability Database (NVD)
DellAlienware M15 R5 Firmware Version < 1.5.0
   DellAlienware M15 R5 Version-
DellG15 5515 Firmware Version < 1.6.0
   DellG15 5515 Version-
DellG5 Se 5505 Firmware Version < 1.11.0
   DellG5 Se 5505 Version-
DellInspiron 27 7775 Firmware Version < 2.16.1
   DellInspiron 27 7775 Version-
DellInspiron 14 5425 Firmware Version < 1.2.1
   DellInspiron 14 5425 Version-
DellInspiron 3275 Firmware Version < 1.9.0
   DellInspiron 3275 Version-
DellInspiron 3475 Firmware Version < 1.9.0
   DellInspiron 3475 Version-
DellInspiron 3180 Firmware Version < 1.4.4
   DellInspiron 3180 Version-
DellInspiron 3185 Firmware Version < 1.4.4
   DellInspiron 3185 Version-
DellInspiron 3195 Firmware Version < 1.4.1
   DellInspiron 3195 Version-
DellInspiron 3505 Firmware Version < 1.6.0
   DellInspiron 3505 Version-
DellInspiron 3515 Firmware Version < 1.5.0
   DellInspiron 3515 Version-
DellInspiron 3525 Firmware Version < 1.3.0
   DellInspiron 3525 Version-
DellInspiron 3585 Firmware Version < 1.7.0
   DellInspiron 3585 Version-
DellInspiron 3595 Firmware Version < 1.3.0
   DellInspiron 3595 Version-
DellInspiron 3785 Firmware Version < 1.7.0
   DellInspiron 3785 Version-
DellInspiron 5405 Firmware Version < 1.7.0
   DellInspiron 5405 Version-
DellInspiron 5415 Firmware Version < 1.9.0
   DellInspiron 5415 Version-
DellInspiron 5485 Firmware Version < 2.8.0
   DellInspiron 5485 Version-
DellInspiron 5505 Firmware Version < 1.7.0
   DellInspiron 5505 Version-
DellInspiron 5515 Firmware Version < 1.9.0
   DellInspiron 5515 Version-
DellInspiron 5575 Firmware Version < 1.6.0
   DellInspiron 5575 Version-
DellInspiron 5585 Firmware Version < 2.8.0
   DellInspiron 5585 Version-
DellInspiron 7375 Firmware Version < 1.7.0
   DellInspiron 7375 Version-
DellInspiron 7405 Firmware Version < 1.8.0
   DellInspiron 7405 Version-
DellInspiron 7415 Firmware Version < 1.9.0
   DellInspiron 7415 Version-
DellInspiron 7425 Firmware Version < 1.2.1
   DellInspiron 7425 Version-
DellVostro 3405 Firmware Version < 1.6.0
   DellVostro 3405 Version-
DellVostro 3515 Firmware Version < 1.5.0
   DellVostro 3515 Version-
DellVostro 3525 Firmware Version < 1.3.0
   DellVostro 3525 Version-
DellVostro 5415 Firmware Version < 1.9.0
   DellVostro 5415 Version-
DellVostro 5515 Firmware Version < 1.9.0
   DellVostro 5515 Version-
DellVostro 5625 Firmware Version < 1.2.1
   DellVostro 5625 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.094
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
security_alert@emc.com 6.3 0.8 5.5
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.