CVE-2022-34400

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
01/02/2023
Last modified:
07/11/2023

Description

<br /> Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM.<br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:alienware_m15_r6_firmware:*:*:*:*:*:*:*:* 1.17.0 (excluding)
cpe:2.3:h:dell:alienware_m15_r6:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_m15_r7_firmware:*:*:*:*:*:*:*:* 1.4.3 (excluding)
cpe:2.3:h:dell:alienware_m15_r7:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_m15_ryzen_edition_r5_firmware:*:*:*:*:*:*:*:* 1.8.0 (excluding)
cpe:2.3:h:dell:alienware_m15_ryzen_edition_r5:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:alienware_m17_r5_amd_firmware:*:*:*:*:*:*:*:* 1.4.3 (excluding)
cpe:2.3:h:dell:alienware_m17_r5_amd:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g15_5510_firmware:*:*:*:*:*:*:*:* 1.16.0 (excluding)
cpe:2.3:h:dell:g15_5510:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g15_5511_firmware:*:*:*:*:*:*:*:* 1.18.0 (excluding)
cpe:2.3:h:dell:g15_5511:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g15_5515_firmware:*:*:*:*:*:*:*:* 1.8.0 (excluding)
cpe:2.3:h:dell:g15_5515:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g15_5525_firmware:*:*:*:*:*:*:*:* 1.4.3 (excluding)


References to Advisories, Solutions, and Tools