CVSS3
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
5.1%
Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.
Vendor | Product | Version | CPE |
---|---|---|---|
dell | alienware_m15_r7_firmware | * | cpe:2.3:o:dell:alienware_m15_r7_firmware:*:*:*:*:*:*:*:* |
dell | alienware_m15_r7 | - | cpe:2.3:h:dell:alienware_m15_r7:-:*:*:*:*:*:*:* |
dell | alienware_m16_firmware | * | cpe:2.3:o:dell:alienware_m16_firmware:*:*:*:*:*:*:*:* |
dell | alienware_m16 | - | cpe:2.3:h:dell:alienware_m16:-:*:*:*:*:*:*:* |
dell | alienware_m18_firmware | * | cpe:2.3:o:dell:alienware_m18_firmware:*:*:*:*:*:*:*:* |
dell | alienware_m18 | - | cpe:2.3:h:dell:alienware_m18:-:*:*:*:*:*:*:* |
dell | chengming_3900_firmware | * | cpe:2.3:o:dell:chengming_3900_firmware:*:*:*:*:*:*:*:* |
dell | chengming_3900 | - | cpe:2.3:h:dell:chengming_3900:-:*:*:*:*:*:*:* |
dell | chengming_3901_firmware | * | cpe:2.3:o:dell:chengming_3901_firmware:*:*:*:*:*:*:*:* |
dell | chengming_3901 | - | cpe:2.3:h:dell:chengming_3901:-:*:*:*:*:*:*:* |