7.5
CVE-2022-34412
- EPSS 0.04%
- Published 16.03.2023 12:15:10
- Last modified 26.02.2025 19:15:13
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service.
Data is provided by the National Vulnerability Database (NVD)
Dell ≫ R6515 Firmware Version < 2.9.3
Dell ≫ R7515 Firmware Version < 2.9.3
Dell ≫ R6525 Firmware Version < 2.9.3
Dell ≫ R7525 Firmware Version < 2.9.3
Dell ≫ Xe8545 Firmware Version < 2.9.4
Dell ≫ R6415 Firmware Version < 1.19.0
Dell ≫ R7415 Firmware Version < 1.19.0
Dell ≫ R7425 Firmware Version < 1.19.0
Dell ≫ R750 Firmware Version < 1.8.2
Dell ≫ R750xa Firmware Version < 1.8.2
Dell ≫ R650 Firmware Version < 1.8.2
Dell ≫ C6520 Firmware Version < 1.8.2
Dell ≫ Mx750c Firmware Version < 1.8.2
Dell ≫ R450 Firmware Version < 1.8.2
Dell ≫ R550 Firmware Version < 1.8.2
Dell ≫ R650xs Firmware Version < 1.8.2
Dell ≫ R750xs Firmware Version < 1.8.2
Dell ≫ T550 Firmware Version < 1.8.2
Dell ≫ Xr11 Firmware Version < 1.8.2
Dell ≫ Xr12 Firmware Version < 1.8.2
Dell ≫ R250 Firmware Version < 1.4.2
Dell ≫ R350 Firmware Version < 1.4.2
Dell ≫ T150 Firmware Version < 1.4.2
Dell ≫ T350 Firmware Version < 1.4.2
Dell ≫ R740 Firmware Version < 2.16.1
Dell ≫ R740xd Firmware Version < 2.16.1
Dell ≫ R640 Firmware Version < 2.16.1
Dell ≫ R940 Firmware Version < 2.16.1
Dell ≫ R540 Firmware Version < 2.16.1
Dell ≫ R440 Firmware Version < 2.16.1
Dell ≫ T440 Firmware Version < 2.16.1
Dell ≫ Xr2 Firmware Version < 2.16.1
Dell ≫ R740xd2 Firmware Version < 2.16.1
Dell ≫ R840 Firmware Version < 2.16.1
Dell ≫ R940xa Firmware Version < 2.16.1
Dell ≫ T640 Firmware Version < 2.16.1
Dell ≫ C6420 Firmware Version < 2.16.1
Dell ≫ Fc640 Firmware Version < 2.16.1
Dell ≫ M640 Firmware Version < 2.16.1
Dell ≫ M640p Firmware Version < 2.16.1
Dell ≫ Mx740c Firmware Version < 2.16.1
Dell ≫ Mx840c Firmware Version < 2.16.1
Dell ≫ C4140 Firmware Version < 2.16.1
Dell ≫ Dss8440 Firmware Version < 2.16.1
Dell ≫ T140 Firmware Version < 2.11.1
Dell ≫ T340 Firmware Version < 2.11.1
Dell ≫ R240 Firmware Version < 2.11.1
Dell ≫ R340 Firmware Version < 2.11.1
Dell ≫ Xe2420 Firmware Version < 2.16.0
Dell ≫ Xe7420 Firmware Version < 2.16.1
Dell ≫ Xe7440 Firmware Version < 2.16.1
Dell ≫ R730 Firmware Version < 2.16.0
Dell ≫ R730xd Firmware Version < 2.16.0
Dell ≫ R630 Firmware Version < 2.16.0
Dell ≫ C4130 Firmware Version < 2.16.0
Dell ≫ R930 Firmware Version < 2.16.0
Dell ≫ M630 Firmware Version < 2.16.0
Dell ≫ M630p Firmware Version < 2.16.0
Dell ≫ Fc630 Firmware Version < 2.16.0
Dell ≫ Fc430 Firmware Version < 2.16.0
Dell ≫ M830 Firmware Version < 2.16.0
Dell ≫ M830p Firmware Version < 2.16.0
Dell ≫ Fc830 Firmware Version < 2.16.0
Dell ≫ T630 Firmware Version < 2.16.0
Dell ≫ R530 Firmware Version < 2.16.0
Dell ≫ R430 Firmware Version < 2.16.0
Dell ≫ T430 Firmware Version < 2.16.0
Dell ≫ R830 Firmware Version < 1.16.0
Dell ≫ C6320 Firmware Version < 2.16.0
Dell ≫ T130 Firmware Version < 2.16.0
Dell ≫ R230 Firmware Version < 2.16.0
Dell ≫ T330 Firmware Version < 2.16.0
Dell ≫ R330 Firmware Version < 2.16.0
Dell ≫ Nx430 Firmware Version < 2.16.0
Dell ≫ Nx3230 Firmware Version < 2.16.0
Dell ≫ Nx3330 Firmware Version < 2.16.0
Dell ≫ Nx440 Firmware Version < 2.11.1
Dell ≫ Nx3240 Firmware Version < 2.16.1
Dell ≫ Nx3340 Firmware Version < 2.16.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.107 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
security_alert@emc.com | 7.5 | 0.8 | 6 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.