6.8

CVE-2023-32480

Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.

Data is provided by the National Vulnerability Database (NVD)
DellAlienware M15 R7 Firmware Version < 1.17.0
   DellAlienware M15 R7 Version-
DellG15 5510 Firmware Version < 1.19.0
   DellG15 5510 Version-
DellG15 5520 Firmware Version < 1.17.0
   DellG15 5520 Version-
DellInspiron 14 5410 Firmware Version < 2.19.1
   DellInspiron 14 5410 Version-
DellInspiron 14 5418 Firmware Version < 2.19.1
   DellInspiron 14 5418 Version-
DellInspiron 15 5510 Firmware Version < 2.19.1
   DellInspiron 15 5510 Version-
DellInspiron 15 5518 Firmware Version < 2.19.1
   DellInspiron 15 5518 Version-
DellInspiron 16 7620 2-in-1 Firmware Version < 1.12.1
   DellInspiron 16 7620 2-in-1 Version-
DellInspiron 3520 Firmware Version < 1.15.0
   DellInspiron 3520 Version-
DellInspiron 5410 Firmware Version < 2.19.1
   DellInspiron 5410 Version-
DellInspiron 5420 Firmware Version < 1.14.1
   DellInspiron 5420 Version-
DellInspiron 5620 Firmware Version < 1.14.1
   DellInspiron 5620 Version-
DellInspiron 7420 Firmware Version < 1.12.1
   DellInspiron 7420 Version-
DellInspiron 7510 Firmware Version < 1.16.1
   DellInspiron 7510 Version-
DellInspiron 7610 Firmware Version < 1.16.1
   DellInspiron 7610 Version-
DellLatitude 3320 Firmware Version < 1.22.2
   DellLatitude 3320 Version-
DellLatitude 3420 Firmware Version < 1.29.0
   DellLatitude 3420 Version-
DellLatitude 3430 Firmware Version < 1.10.1
   DellLatitude 3430 Version-
DellLatitude 3520 Firmware Version < 1.29.0
   DellLatitude 3520 Version-
DellLatitude 3530 Firmware Version < 1.10.1
   DellLatitude 3530 Version-
DellPrecision 5760 Firmware Version < 1.20.1
   DellPrecision 5760 Version-
DellPrecision 5770 Firmware Version < 1.17.1
   DellPrecision 5770 Version-
DellVostro 3420 Firmware Version < 1.15.0
   DellVostro 3420 Version-
DellVostro 3520 Firmware Version < 1.15.0
   DellVostro 3520 Version-
DellVostro 5410 Firmware Version < 2.19.1
   DellVostro 5410 Version-
DellVostro 5510 Firmware Version < 2.19.1
   DellVostro 5510 Version-
DellVostro 5620 Firmware Version < 1.14.1
   DellVostro 5620 Version-
DellVostro 7510 Firmware Version < 1.16.1
   DellVostro 7510 Version-
DellXps 13 9315 2-in-1 Firmware Version < 1.8.1
   DellXps 13 9315 2-in-1 Version-
DellXps 17 9710 Firmware Version < 1.20.1
   DellXps 17 9710 Version-
DellXps 17 9720 Firmware Version < 1.17.1
   DellXps 17 9720 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.184
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security_alert@emc.com 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.