CVE-2022-32482

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
01/02/2023
Last modified:
07/11/2023

Description

<br /> Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.<br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:dell:alienware_m15_r6:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_m15_r6_firmware:*:*:*:*:*:*:*:* 1.17.0 (excluding)
cpe:2.3:h:dell:alienware_m15_r7:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_m15_r7_firmware:*:*:*:*:*:*:*:* 1.10.0 (excluding)
cpe:2.3:o:dell:chengming_3900_firmware:*:*:*:*:*:*:*:* 1.7.3 (excluding)
cpe:2.3:h:dell:chengming_3900:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:g15_5510:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g15_5510_firmware:*:*:*:*:*:*:*:* 1.16.0 (excluding)
cpe:2.3:h:dell:g15_5511:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g15_5511_firmware:*:*:*:*:*:*:*:* 1.18.0 (excluding)
cpe:2.3:h:dell:g15_5520:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g15_5520_firmware:*:*:*:*:*:*:*:* 1.10.0 (excluding)
cpe:2.3:h:dell:g16_7620:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g16_7620_firmware:*:*:*:*:*:*:*:* 1.12.0 (excluding)
cpe:2.3:h:dell:g3_3500:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools