7.6

CVE-2023-32475

Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Vostro 5625 Firmware Version < 1.13.0
   Dell ≫ Vostro 5625 Version -
Dell ≫ Vostro 5515 Firmware Version < 1.19.0
   Dell ≫ Vostro 5515 Version -
Dell ≫ Vostro 5415 Firmware Version < 1.19.0
   Dell ≫ Vostro 5415 Version -
Dell ≫ Vostro 3405 Firmware Version < 1.16.0
   Dell ≫ Vostro 3405 Version -
Dell ≫ Vostro 16 5635 Firmware Version < 1.8.0
   Dell ≫ Vostro 16 5635 Version -
Dell ≫ Vostro 15 3535 Firmware Version < 1.12.0
   Dell ≫ Vostro 15 3535 Version -
Dell ≫ Vostro 15 3525 Firmware Version < 1.15.1
   Dell ≫ Vostro 15 3525 Version -
Dell ≫ Vostro 15 3515 Firmware Version < 1.16.0
   Dell ≫ Vostro 15 3515 Version -
Dell ≫ Vostro 14 3435 Firmware Version < 1.12.0
   Dell ≫ Vostro 14 3435 Version -
Dell ≫ Vostro 14 3425 Firmware Version < 1.15.1
   Dell ≫ Vostro 14 3425 Version -
Dell ≫ Inspiron 7415 2-in-1 Firmware Version < 1.19.0
   Dell ≫ Inspiron 7415 2-in-1 Version -
Dell ≫ Inspiron 7405 2-in-1 Firmware Version < 1.15.0
   Dell ≫ Inspiron 7405 2-in-1 Version -
Dell ≫ Inspiron 5515 Firmware Version < 1.19.0
   Dell ≫ Inspiron 5515 Version -
Dell ≫ Inspiron 5505 Firmware Version < 1.14.0
   Dell ≫ Inspiron 5505 Version -
Dell ≫ Inspiron 5415 Firmware Version < 1.19.0
   Dell ≫ Inspiron 5415 Version -
Dell ≫ Inspiron 5405 Firmware Version < 1.14.0
   Dell ≫ Inspiron 5405 Version -
Dell ≫ Inspiron 3505 Firmware Version < 1.16.0
   Dell ≫ Inspiron 3505 Version -
Dell ≫ Inspiron 16 7635 2-in-1 Firmware Version < 1.8.0
   Dell ≫ Inspiron 16 7635 2-in-1 Version -
Dell ≫ Inspiron 16 5635 Firmware Version < 1.8.0
   Dell ≫ Inspiron 16 5635 Version -
Dell ≫ Inspiron 16 5625 Firmware Version < 1.13.0
   Dell ≫ Inspiron 16 5625 Version -
Dell ≫ Inspiron 15 3535 Firmware Version < 1.12.0
   Dell ≫ Inspiron 15 3535 Version -
Dell ≫ Inspiron 15 3525 Firmware Version < 1.15.1
   Dell ≫ Inspiron 15 3525 Version -
Dell ≫ Inspiron 15 3515 Firmware Version < 1.16.0
   Dell ≫ Inspiron 15 3515 Version -
Dell ≫ Inspiron 14 7435 2-in-1 Firmware Version < 1.8.0
   Dell ≫ Inspiron 14 7435 2-in-1 Version -
Dell ≫ Inspiron 14 7425 2-in-1 Firmware Version < 1.13.0
   Dell ≫ Inspiron 14 7425 2-in-1 Version -
Dell ≫ Inspiron 14 5435 Firmware Version < 1.8.0
   Dell ≫ Inspiron 14 5435 Version -
Dell ≫ Inspiron 14 5425 Firmware Version < 1.13.0
   Dell ≫ Inspiron 14 5425 Version -
Dell ≫ G5 5505 Firmware Version < 1.18.0
   Dell ≫ G5 5505 Version -
Dell ≫ G15 5535 Firmware Version < 1.5.0
   Dell ≫ G15 5535 Version -
Dell ≫ G15 5525 Firmware Version < 1.15.0
   Dell ≫ G15 5525 Version -
Dell ≫ G15 5515 Firmware Version < 1.15.0
   Dell ≫ G15 5515 Version -
Dell ≫ Alienware M18 Firmware Version < 1.9.0
   Dell ≫ Alienware M18 Version -
Dell ≫ Alienware M17 R5 Amd Firmware Version < 1.15.0
   Dell ≫ Alienware M17 R5 Amd Version -
Dell ≫ Alienware M16 R1 Amd Firmware Version < 1.9.0
   Dell ≫ Alienware M16 R1 Amd Version -
Dell ≫ Alienware M15 R7 Amd Firmware Version < 1.15.0
   Dell ≫ Alienware M15 R7 Amd Version -
Dell ≫ Alienware Aurora R15 Amd Firmware Version < 1.13.0
   Dell ≫ Alienware Aurora R15 Amd Version -
Dell ≫ Alienware Aurora R10 Firmware Version < 2.6.0
   Dell ≫ Alienware Aurora R10 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.6 0.9 6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EMC 7.6 0.9 6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-353 Missing Support for Integrity Check

The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.

https://www.dell.com/support/kbdoc/en-us/000215644/dsa-2023-222-security-update-for-an-amd-bios-vulnerability
Vendor Advisory