4.4

CVE-2022-31222

Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by consuming excess memory in order to cause the application to crash.

Data is provided by the National Vulnerability Database (NVD)
DellChengming 3900 Firmware Version < 1.1.66
   DellChengming 3900 Version-
DellInspiron 14 Plus 7420 Firmware Version < 1.2.0
   DellInspiron 14 Plus 7420 Version-
DellInspiron 16 Plus 7620 Firmware Version < 1.2.0
   DellInspiron 16 Plus 7620 Version-
DellInspiron 3910 Firmware Version < 1.1.66
   DellInspiron 3910 Version-
DellInspiron 5320 Firmware Version < 1.1.0
   DellInspiron 5320 Version-
DellInspiron 5420 Firmware Version < 1.4.1
   DellInspiron 5420 Version-
DellInspiron 5620 Firmware Version < 1.4.1
   DellInspiron 5620 Version-
DellInspiron 7420 Firmware Version < 1.3.0
   DellInspiron 7420 Version-
DellInspiron 7620 Firmware Version < 1.3.0
   DellInspiron 7620 Version-
DellOptiplex 3000 Firmware Version < 1.1.66
   DellOptiplex 3000 Version-
DellOptiplex 5000 Firmware Version < 1.3.62
   DellOptiplex 5000 Version-
DellOptiplex 5400 Firmware Version < 1.0.13
   DellOptiplex 5400 Version-
DellOptiplex 7000 Firmware Version < 1.3.62
   DellOptiplex 7000 Version-
DellOptiplex 7000 Oem Firmware Version < 1.3.62
   DellOptiplex 7000 Oem Version-
DellOptiplex 7400 Firmware Version < 1.0.13
   DellOptiplex 7400 Version-
DellPrecision 3660 Tower Firmware Version < 1.3.71
   DellPrecision 3660 Tower Version-
DellPrecision 5770 Firmware Version < 1.6.0
   DellPrecision 5770 Version-
DellVostro 3710 Firmware Version < 1.1.66
   DellVostro 3710 Version-
DellVostro 3910 Firmware Version < 1.1.66
   DellVostro 3910 Version-
DellVostro 5320 Firmware Version < 1.1.0
   DellVostro 5320 Version-
DellVostro 5620 Firmware Version < 1.4.1
   DellVostro 5620 Version-
DellVostro 7620 Firmware Version < 1.2.0
   DellVostro 7620 Version-
DellXps 17 9720 Firmware Version < 1.6.0
   DellXps 17 9720 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.125
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
security_alert@emc.com 2.3 0.8 1.4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.

CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.