Lucene search

K
cve[email protected]CVE-2022-34419
HistoryMar 16, 2023 - 12:15 p.m.

CVE-2022-34419

2023-03-1612:15:10
CWE-119
web.nvd.nist.gov
26
cve-2022-34419
dell
bios
smm
buffer
verification
vulnerability
arbitrary code execution
denial of service

7.5 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service.

Affected configurations

NVD
Node
dellr6515_firmwareRange<2.9.3
AND
dellr6515Match-
Node
dellr7515_firmwareRange<2.9.3
AND
dellr7515Match-
Node
dellr6525_firmwareRange<2.9.3
AND
dellr6525Match-
Node
dellr7525_firmwareRange<2.9.3
AND
dellr7525Match-
Node
dellxe8545_firmwareRange<2.9.4
AND
dellxe8545Match-
Node
dellc6525_firmware
AND
dellc6525Match-
Node
dellr6415_firmwareRange<1.19.0
AND
dellr6415Match-
Node
dellr7415_firmwareRange<1.19.0
AND
dellr7415Match-
Node
dellr7425_firmwareRange<1.19.0
AND
dellr7425Match-
Node
dellr750_firmwareRange<1.8.2
AND
dellr750Match-
Node
dellr750xa_firmwareRange<1.8.2
AND
dellr750xaMatch-
Node
dellr650_firmwareRange<1.8.2
AND
dellr650Match-
Node
dellc6520_firmwareRange<1.8.2
AND
dellc6520Match-
Node
dellmx750c_firmwareRange<1.8.2
AND
dellmx750cMatch-
Node
dellr450_firmwareRange<1.8.2
AND
dellr450Match-
Node
dellr550_firmwareRange<1.8.2
AND
dellr550Match-
Node
dellr650xs_firmwareRange<1.8.2
AND
dellr650xsMatch-
Node
dellr750xs_firmwareRange<1.8.2
AND
dellr750xsMatch-
Node
dellt550_firmwareRange<1.8.2
AND
dellt550Match-
Node
dellxr11_firmwareRange<1.8.2
AND
dellxr11Match-
Node
dellxr12_firmwareRange<1.8.2
AND
dellxr12Match-
Node
dellr250_firmwareRange<1.4.2
AND
dellr250Match-
Node
dellr350_firmwareRange<1.4.2
AND
dellr350Match-
Node
dellt150_firmwareRange<1.4.2
AND
dellt150Match-
Node
dellt350_firmwareRange<1.4.2
AND
dellt350Match-
Node
dellr740_firmwareRange<2.16.1
AND
dellr740Match-
Node
dellr740xd_firmwareRange<2.16.1
AND
dellr740xdMatch-
Node
dellr640_firmwareRange<2.16.1
AND
dellr640Match-
Node
dellr940_firmwareRange<2.16.1
AND
dellr940Match-
Node
dellr540_firmwareRange<2.16.1
AND
dellr540Match-
Node
dellr440_firmwareRange<2.16.1
AND
dellr440Match-
Node
dellt440_firmwareRange<2.16.1
AND
dellt440Match-
Node
dellxr2_firmwareRange<2.16.1
AND
dellxr2Match-
Node
dellr740xd2_firmwareRange<2.16.1
AND
dellr740xd2Match-
Node
dellr840_firmwareRange<2.16.1
AND
dellr840Match-
Node
dellr940xa_firmwareRange<2.16.1
AND
dellr940xaMatch-
Node
dellt640_firmwareRange<2.16.1
AND
dellt640Match-
Node
dellc6420_firmwareRange<2.16.1
AND
dellc6420Match-
Node
dellfc640_firmwareRange<2.16.1
AND
dellfc640Match-
Node
dellm640_firmwareRange<2.16.1
AND
dellm640Match-
Node
dellm640p_firmwareRange<2.16.1
AND
dellm640pMatch-
Node
dellmx740c_firmwareRange<2.16.1
AND
dellmx740cMatch-
Node
dellmx840c_firmwareRange<2.16.1
AND
dellmx840cMatch-
Node
dellc4140_firmwareRange<2.16.1
AND
dellc4140Match-
Node
delldss8440_firmwareRange<2.16.1
AND
delldss8440Match-
Node
dellt140_firmwareRange<2.11.1
AND
dellt140Match-
Node
dellt340_firmwareRange<2.11.1
AND
dellt340Match-
Node
dellr240_firmwareRange<2.11.1
AND
dellr240Match-
Node
dellr340_firmwareRange<2.11.1
AND
dellr340Match-
Node
dellxe2420_firmwareRange<2.16.0
AND
dellxe2420Match-
Node
dellxe7420_firmwareRange<2.16.1
AND
dellxe7420Match-
Node
dellxe7440_firmwareRange<2.16.1
AND
dellxe7440Match-
Node
dellr730_firmwareRange<2.16.0
AND
dellr730Match-
Node
dellr730xd_firmwareRange<2.16.0
AND
dellr730xdMatch-
Node
dellr630_firmwareRange<2.16.0
AND
dellr630Match-
Node
dellc4130_firmwareRange<2.16.0
AND
dellc4130Match-
Node
dellr930_firmwareRange<2.16.0
AND
dellr930Match-
Node
dellm630_firmwareRange<2.16.0
AND
dellm630Match-
Node
dellm630p_firmwareRange<2.16.0
AND
dellm630pMatch-
Node
dellfc630_firmwareRange<2.16.0
AND
dellfc630Match-
Node
dellfc430_firmwareRange<2.16.0
AND
dellfc430Match-
Node
dellm830_firmwareRange<2.16.0
AND
dellm830Match-
Node
dellm830p_firmwareRange<2.16.0
AND
dellm830pMatch-
Node
dellfc830_firmwareRange<2.16.0
AND
dellfc830Match-
Node
dellt630_firmwareRange<2.16.0
AND
dellt630Match-
Node
dellr530_firmwareRange<2.16.0
AND
dellr530Match-
Node
dellr430_firmwareRange<2.16.0
AND
dellr430Match-
Node
dellt430_firmwareRange<2.16.0
AND
dellt430Match-
Node
dellr830_firmwareRange<1.16.0
AND
dellr830Match-
Node
dellc6320_firmwareRange<2.16.0
AND
dellc6320Match-
Node
dellt130_firmwareRange<2.16.0
AND
dellt130Match-
Node
dellr230_firmwareRange<2.16.0
AND
dellr230Match-
Node
dellt330_firmwareRange<2.16.0
AND
dellt330Match-
Node
dellr330_firmwareRange<2.16.0
AND
dellr330Match-
Node
dellnx430_firmwareRange<2.16.0
AND
dellnx430Match-
Node
dellnx3230_firmwareRange<2.16.0
AND
dellnx3230Match-
Node
dellnx3330_firmwareRange<2.16.0
AND
dellnx3330Match-
Node
dellnx440_firmwareRange<2.11.1
AND
dellnx440Match-
Node
dellnx3240_firmwareRange<2.16.1
AND
dellnx3240Match-
Node
dellnx3340_firmwareRange<2.16.1
AND
dellnx3340Match-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "PowerEdge Platform",
    "vendor": "Dell",
    "versions": [
      {
        "status": "affected",
        "version": "14G,15G"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2022-34419