HIGH
Dell BIOS contains a stack based buffer overflow vulnerability
Published Jan 18, 2023
7.5
HIGHCVSS 3.1
EPSS 0.17%
Description
Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM.
Affected products
-
Affected
- 1.4.3
Configuration 1
AND
- < 1.4.3
Running on/with
- n/a
Configuration 2
AND
- < 1.4.3
Running on/with
- n/a
Configuration 3
AND
- < 1.4.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37356 Advisory
- https://www.dell.com/support/kbdoc/000204679 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37356 | Advisory | |
| https://www.dell.com/support/kbdoc/000204679 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published Jan 18, 2023
Updated Apr 3, 2025
Reserved Jun 23, 2022
Link CVE-2022-34401
CISA Vulnrichment
Updated Apr 2, 2025
Red Hat
No data
GitHub
No data