6

CVE-2023-32471

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Edge Gateway 3200 Firmware Version -
   Dell ≫ Edge Gateway 3200 Version -
Dell ≫ Edge Gateway 5200 Firmware Version -
   Dell ≫ Edge Gateway 5200 Version -
Dell ≫ Precision 3930 Rack Firmware Version -
   Dell ≫ Precision 3930 Rack Version -
Dell ≫ Optiplex 7080 Firmware Version -
   Dell ≫ Optiplex 7080 Version -
Dell ≫ Precision 5520 Firmware Version -
   Dell ≫ Precision 5520 Version -
Dell ≫ Inspiron 7460 Firmware Version -
   Dell ≫ Inspiron 7460 Version -
Dell ≫ Precision 5820 Tower Firmware Version -
   Dell ≫ Precision 5820 Tower Version -
Dell ≫ G5 5587 Firmware Version -
   Dell ≫ G5 5587 Version -
Dell ≫ G7 7588 Firmware Version -
   Dell ≫ G7 7588 Version -
Dell ≫ Vostro 15 7580 Firmware Version -
   Dell ≫ Vostro 15 7580 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6 1.5 4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
EMC 6 1.5 4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://www.dell.com/support/kbdoc/en-us/000214917/dsa-2023-225-security-update-for-dell-bios-edge-gateway-5200-and-edge-gateway-3200
Vendor Advisory