CVE-2022-34460
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
18/01/2023
Last modified:
07/11/2023
Description
<br />
Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.<br />
<br />
<br />
<br />
<br />
<br />
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dell:g5_se_5505_firmware:*:*:*:*:*:*:*:* | 1.12.1 (excluding) | |
| cpe:2.3:h:dell:g5_se_5505:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:inspiron_27_7775_firmware:*:*:*:*:*:*:*:* | 2.17.0 (excluding) | |
| cpe:2.3:h:dell:inspiron_27_7775:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:inspiron_3180_firmware:*:*:*:*:*:*:*:* | 1.5.0 (excluding) | |
| cpe:2.3:h:dell:inspiron_3180:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:inspiron_3185_firmware:*:*:*:*:*:*:*:* | 1.5.0 (excluding) | |
| cpe:2.3:h:dell:inspiron_3185:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:inspiron_3195_2-in-1_firmware:*:*:*:*:*:*:*:* | 1.5.0 (excluding) | |
| cpe:2.3:h:dell:inspiron_3195_2-in-1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:inspiron_3275_firmware:*:*:*:*:*:*:*:* | 1.9.1 (excluding) | |
| cpe:2.3:h:dell:inspiron_3275:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:inspiron_3475_firmware:*:*:*:*:*:*:*:* | 1.9.1 (excluding) | |
| cpe:2.3:h:dell:inspiron_3475:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dell:inspiron_3505_firmware:*:*:*:*:*:*:*:* | 1.8.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



