7.5

CVE-2022-34393

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.





Data is provided by the National Vulnerability Database (NVD)
DellG5 Se 5505 Firmware Version < 1.12.1
   DellG5 Se 5505 Version-
DellInspiron 27 7775 Firmware Version < 2.17.0
   DellInspiron 27 7775 Version-
DellInspiron 3180 Firmware Version < 1.5.0
   DellInspiron 3180 Version-
DellInspiron 3185 Firmware Version < 1.5.0
   DellInspiron 3185 Version-
DellInspiron 3195 2-in-1 Firmware Version < 1.5.0
   DellInspiron 3195 2-in-1 Version-
DellInspiron 3275 Firmware Version < 1.9.1
   DellInspiron 3275 Version-
DellInspiron 3475 Firmware Version < 1.9.1
   DellInspiron 3475 Version-
DellInspiron 3505 Firmware Version < 1.8.0
   DellInspiron 3505 Version-
DellInspiron 3515 Firmware Version < 1.7.0
   DellInspiron 3515 Version-
DellInspiron 3585 Firmware Version < 1.9.0
   DellInspiron 3585 Version-
DellInspiron 3595 Firmware Version < 1.4.0
   DellInspiron 3595 Version-
DellInspiron 3785 Firmware Version < 1.9.0
   DellInspiron 3785 Version-
DellInspiron 5405 Firmware Version < 1.8.1
   DellInspiron 5405 Version-
DellInspiron 5415 Firmware Version < 1.12.0
   DellInspiron 5415 Version-
DellInspiron 5485 Firmware Version < 2.10.1
   DellInspiron 5485 Version-
DellInspiron 5485 2-in-1 Firmware Version < 2.10.1
   DellInspiron 5485 2-in-1 Version-
DellInspiron 5505 Firmware Version < 1.8.1
   DellInspiron 5505 Version-
DellInspiron 5515 Firmware Version < 1.12.0
   DellInspiron 5515 Version-
DellInspiron 5585 Firmware Version < 2.10.1
   DellInspiron 5585 Version-
DellInspiron 7375 Firmware Version < 1.9.0
   DellInspiron 7375 Version-
DellInspiron 7405 2-in-1 Firmware Version < 1.9.1
   DellInspiron 7405 2-in-1 Version-
DellInspiron 7415 Firmware Version < 1.12.0
   DellInspiron 7415 Version-
DellVostro 3405 Firmware Version < 1.8.0
   DellVostro 3405 Version-
DellVostro 3515 Firmware Version < 1.7.0
   DellVostro 3515 Version-
DellVostro 5415 Firmware Version < 1.12.0
   DellVostro 5415 Version-
DellVostro 5515 Firmware Version < 1.12.0
   DellVostro 5515 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.045
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
security_alert@emc.com 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.