CVE-2022-31223

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/09/2022
Last modified:
15/09/2022

Description

Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read memory on the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:chengming_3900_firmware:*:*:*:*:*:*:*:* 1.1.66 (excluding)
cpe:2.3:h:dell:chengming_3900:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_14_plus_7420_firmware:*:*:*:*:*:*:*:* 1.2.0 (excluding)
cpe:2.3:h:dell:inspiron_14_plus_7420:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_16_plus_7620_firmware:*:*:*:*:*:*:*:* 1.2.0 (excluding)
cpe:2.3:h:dell:inspiron_16_plus_7620:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_3910_firmware:*:*:*:*:*:*:*:* 1.1.66 (excluding)
cpe:2.3:h:dell:inspiron_3910:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_5320_firmware:*:*:*:*:*:*:*:* 1.1.0 (excluding)
cpe:2.3:h:dell:inspiron_5320:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_5420_firmware:*:*:*:*:*:*:*:* 1.4.1 (excluding)
cpe:2.3:h:dell:inspiron_5420:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_5620_firmware:*:*:*:*:*:*:*:* 1.4.1 (excluding)
cpe:2.3:h:dell:inspiron_5620:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_7420_firmware:*:*:*:*:*:*:*:* 1.3.0 (excluding)


References to Advisories, Solutions, and Tools