CVE-2022-34460

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
18/01/2023
Last modified:
07/11/2023

Description

<br /> Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.<br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:g5_se_5505_firmware:*:*:*:*:*:*:*:* 1.12.1 (excluding)
cpe:2.3:h:dell:g5_se_5505:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_27_7775_firmware:*:*:*:*:*:*:*:* 2.17.0 (excluding)
cpe:2.3:h:dell:inspiron_27_7775:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_3180_firmware:*:*:*:*:*:*:*:* 1.5.0 (excluding)
cpe:2.3:h:dell:inspiron_3180:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_3185_firmware:*:*:*:*:*:*:*:* 1.5.0 (excluding)
cpe:2.3:h:dell:inspiron_3185:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_3195_2-in-1_firmware:*:*:*:*:*:*:*:* 1.5.0 (excluding)
cpe:2.3:h:dell:inspiron_3195_2-in-1:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_3275_firmware:*:*:*:*:*:*:*:* 1.9.1 (excluding)
cpe:2.3:h:dell:inspiron_3275:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_3475_firmware:*:*:*:*:*:*:*:* 1.9.1 (excluding)
cpe:2.3:h:dell:inspiron_3475:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_3505_firmware:*:*:*:*:*:*:*:* 1.8.0 (excluding)


References to Advisories, Solutions, and Tools