2.3
CVE-2022-31221
- EPSS 0.05%
- Veröffentlicht 12.09.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 07:04:09
- Quelle security_alert@emc.com
- Teams Watchlist Login
- Unerledigt Login
Dell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order access sensitive state information on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Chengming 3900 Firmware Version < 1.1.66
Dell ≫ Inspiron 14 Plus 7420 Firmware Version < 1.2.0
Dell ≫ Inspiron 16 Plus 7620 Firmware Version < 1.2.0
Dell ≫ Inspiron 3910 Firmware Version < 1.1.66
Dell ≫ Inspiron 5320 Firmware Version < 1.1.0
Dell ≫ Inspiron 5420 Firmware Version < 1.4.1
Dell ≫ Inspiron 5620 Firmware Version < 1.4.1
Dell ≫ Inspiron 7420 Firmware Version < 1.3.0
Dell ≫ Inspiron 7620 Firmware Version < 1.3.0
Dell ≫ Optiplex 3000 Firmware Version < 1.1.66
Dell ≫ Optiplex 3000 Thin Client Firmware Version < 1.0.7
Dell ≫ Optiplex 5000 Firmware Version < 1.3.62
Dell ≫ Optiplex 5400 Firmware Version < 1.0.13
Dell ≫ Optiplex 7000 Firmware Version < 1.3.62
Dell ≫ Optiplex 7000 Oem Firmware Version < 1.3.62
Dell ≫ Optiplex 7400 Firmware Version < 1.0.13
Dell ≫ Precision 3460 Small Form Factor Firmware Version < 1.3.62
Dell ≫ Precision 3660 Tower Firmware Version < 1.3.71
Dell ≫ Precision 5770 Firmware Version < 1.6.0
Dell ≫ Vostro 3710 Firmware Version < 1.1.66
Dell ≫ Vostro 3910 Firmware Version < 1.1.66
Dell ≫ Vostro 5320 Firmware Version < 1.1.0
Dell ≫ Vostro 5620 Firmware Version < 1.4.1
Dell ≫ Vostro 7620 Firmware Version < 1.2.0
Dell ≫ Xps 17 9720 Firmware Version < 1.6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.138 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 2.3 | 0.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
|
security_alert@emc.com | 2.3 | 0.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.