CVE-2022-26861

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/09/2022
Last modified:
14/09/2022

Description

Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution during SMM.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:alienware_m15_r6_firmware:*:*:*:*:*:*:*:* 1.8.0 (excluding)
cpe:2.3:h:dell:alienware_m15_r6:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:chengming_3980_firmware:*:*:*:*:*:*:*:* 2.21.0 (excluding)
cpe:2.3:h:dell:chengming_3980:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:chengming_3988_firmware:*:*:*:*:*:*:*:* 1.9.0 (excluding)
cpe:2.3:h:dell:chengming_3988:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:chengming_3990_firmware:*:*:*:*:*:*:*:* 1.8.2 (excluding)
cpe:2.3:h:dell:chengming_3990:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:chengming_3991_firmware:*:*:*:*:*:*:*:* 1.8.2 (excluding)
cpe:2.3:h:dell:chengming_3991:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g15_5510_firmware:*:*:*:*:*:*:*:* 1.8.0 (excluding)
cpe:2.3:h:dell:g15_5510:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g15_5511_firmware:*:*:*:*:*:*:*:* 1.9.0 (excluding)
cpe:2.3:h:dell:g15_5511:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g3_15_3590_firmware:*:*:*:*:*:*:*:* 1.16.0 (excluding)


References to Advisories, Solutions, and Tools