CVE-2022-32490

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:edge_gateway_3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_3000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:edge_gateway_5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_5000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dell:embedded_box_pc_3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:embedded_box_pc_3000:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 7.5
Summary
  • (es) Dell BIOS contiene una vulnerabilidad de validación de entrada incorrecta. Un usuario malicioso autenticado local podría explotar esta vulnerabilidad utilizando un SMI para obtener la ejecución de código arbitrario en SMRAM.
References () https://www.dell.com/support/kbdoc/000204685 - Vendor Advisory () https://www.dell.com/support/kbdoc/000204685 - Vendor Advisory

Information

Published : 2023-01-18 06:15

Updated : 2024-11-21 07:06


NVD link : CVE-2022-32490

Mitre link : CVE-2022-32490

CVE.ORG link : CVE-2022-32490


JSON object : View

Products Affected

dell

  • edge_gateway_3000_firmware
  • edge_gateway_3000
  • embedded_box_pc_3000
  • edge_gateway_5000
  • embedded_box_pc_3000_firmware
  • edge_gateway_5000_firmware
CWE
CWE-20

Improper Input Validation