Dell BIOS contains an Improper Authorization vulnerability
Published Mar 8, 2023
4.6
MEDIUMCVSS 3.1
EPSS 0.29%
Description
Dell BIOS contains an Improper Authorization vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability, leading to denial of service.
Affected products
-
- Version 1.10.0StatusaffectedConstraints-
- Version 1.11.0StatusaffectedConstraints-
- Version 1.13.1StatusaffectedConstraints-
- Version 1.14.0StatusaffectedConstraints-
- Version 1.16.0StatusaffectedConstraints-
- Version 1.16.1StatusaffectedConstraints-
- Version 1.17.0StatusaffectedConstraints-
- Version 1.17.1StatusaffectedConstraints-
- Version 1.18.0StatusaffectedConstraints-
- Version 1.18.1StatusaffectedConstraints-
- Version 1.19.0StatusaffectedConstraints-
- Version 1.2.0StatusaffectedConstraints-
- Version 1.22.0StatusaffectedConstraints-
- Version 1.24.0StatusaffectedConstraints-
- Version 1.25.1StatusaffectedConstraints-
- Version 1.4.0StatusaffectedConstraints-
- Version 1.6.1StatusaffectedConstraints-
- Version 1.7.0StatusaffectedConstraints-
- Version 1.8.0StatusaffectedConstraints-
- Version 1.8.1StatusaffectedConstraints-
- Version 1.8.2StatusaffectedConstraints-
- Version 1.8.3StatusaffectedConstraints-
- Version 1.9.0StatusaffectedConstraints-
- Version 1.9.1StatusaffectedConstraints-
- Version 2.16.0StatusaffectedConstraints-
- Version 2.16.1StatusaffectedConstraints-
- Version 2.17.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Dell | Cpg Bios | unaffected |
|
Configuration 1
- < 1.8.0
Running on/with
- n/a
Configuration 2
- < 1.8.0
Running on/with
- n/a
Configuration 3
- < 1.19.0
Running on/with
- n/a
Configuration 4
- < 1.9.0
Running on/with
- n/a
Configuration 5
- < 2.17.0
Running on/with
- n/a
Configuration 6
- < 1.7.0
Running on/with
- n/a
Configuration 7
- < 2.16.0
Running on/with
- n/a
Configuration 8
- < 1.10.0
Running on/with
- n/a
Configuration 9
- < 2.16.0
Running on/with
- n/a
Configuration 10
- < 1.10.0
Running on/with
- n/a
Configuration 11
- < 1.8.0
Running on/with
- n/a
Configuration 12
- < 1.14.0
Running on/with
- n/a
Configuration 13
- < 1.14.0
Running on/with
- n/a
Configuration 14
- < 1.8.0
Running on/with
- n/a
Configuration 15
- < 1.2.0
Running on/with
- n/a
Configuration 16
- < 1.19.0
Running on/with
- n/a
Configuration 17
- < 1.10.0
Running on/with
- n/a
Configuration 18
- < 1.25.1
Running on/with
- n/a
Configuration 19
- < 1.7.0
Running on/with
- n/a
Configuration 20
- < 1.25.1
Running on/with
- n/a
Configuration 21
- < 1.7.0
Running on/with
- n/a
Configuration 22
- < 1.8.0
Running on/with
- n/a
Configuration 23
- < 1.24.0
Running on/with
- n/a
Configuration 24
- < 1.8.3
Running on/with
- n/a
Configuration 25
- < 1.14.0
Running on/with
- n/a
Configuration 26
- < 1.8.1
Running on/with
- n/a
Configuration 27
- < 1.25.1
Running on/with
- n/a
Configuration 28
- < 1.18.0
Running on/with
- n/a
Configuration 29
- < 1.8.2
Running on/with
- n/a
Configuration 30
- < 1.9.0
Running on/with
- n/a
Configuration 31
- < 1.22.0
Running on/with
- n/a
Configuration 32
- < 1.18.0
Running on/with
- n/a
Configuration 33
- < 1.10.0
Running on/with
- n/a
Configuration 34
- < 1.22.0
Running on/with
- n/a
Configuration 35
- < 1.10.0
Running on/with
- n/a
Configuration 36
- < 1.22.0
Running on/with
- n/a
Configuration 37
- < 1.10.0
Running on/with
- n/a
Configuration 38
- < 1.8.0
Running on/with
- n/a
Configuration 39
- < 1.17.0
Running on/with
- n/a
Configuration 40
- < 1.9.1
Running on/with
- n/a
Configuration 41
- < 1.17.1
Running on/with
- n/a
Configuration 42
- < 1.18.1
Running on/with
- n/a
Configuration 43
- < 1.14.0
Running on/with
- n/a
Configuration 44
- < 1.17.0
Running on/with
- n/a
Configuration 45
- < 1.8.1
Running on/with
- n/a
Configuration 46
- < 1.25.1
Running on/with
- n/a
Configuration 47
- < 1.18.0
Running on/with
- n/a
Configuration 48
- < 1.8.2
Running on/with
- n/a
Configuration 49
- < 1.9.0
Running on/with
- n/a
Configuration 50
- < 1.9.1
Running on/with
- n/a
Configuration 51
- < 1.16.0
Running on/with
- n/a
Configuration 52
- < 1.9.1
Running on/with
- n/a
Configuration 53
- < 1.16.1
Running on/with
- n/a
Configuration 54
- < 1.13.1
Running on/with
- n/a
Configuration 55
- < 1.18.0
Running on/with
- n/a
Configuration 56
- < 1.8.0
Running on/with
- n/a
Configuration 57
- < 1.18.0
Running on/with
- n/a
Configuration 58
- < 1.8.0
Running on/with
- n/a
Configuration 59
- < 1.9.0
Running on/with
- n/a
Configuration 60
- < 1.19.0
Running on/with
- n/a
Configuration 61
- < 1.9.0
Running on/with
- n/a
Configuration 62
- < 2.17.0
Running on/with
- n/a
Configuration 63
- < 1.7.0
Running on/with
- n/a
Configuration 64
- < 2.16.0
Running on/with
- n/a
Configuration 65
- < 2.16.0
Running on/with
- n/a
Configuration 66
- < 1.10.0
Running on/with
- n/a
Configuration 67
- < 1.14.0
Running on/with
- n/a
Configuration 68
- < 1.8.0
Running on/with
- n/a
Configuration 69
- < 1.6.1
Running on/with
- n/a
Configuration 70
- < 1.4.0
Running on/with
- n/a
Configuration 71
- < 1.11.0
Running on/with
- n/a
Configuration 72
- < 1.16.0
Running on/with
- n/a
Configuration 73
- < 1.9.1
Running on/with
- n/a
Configuration 74
- < 1.16.1
Running on/with
- n/a
Configuration 75
- < 1.13.1
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 28, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.29% (0.00287) | 19.32th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.29% (0.00287) | 20.21th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00069) | 18.53th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00054) | 23.74th | v3 (v2023.03.01) |
| May 11, 2024 | 0.05% (0.00049) | 17.14th | v3 (v2023.03.01) |
| Mar 16, 2023 | 0.05% (0.00049) | 15.13th | v3 (v2023.03.01) |
| Mar 9, 2023 | 0.04% (0.00044) | 8.37th | v3 (v2023.03.01) |
References (1)
- https://www.dell.com/support/kbdoc/en-us/000207928/dsa-2023-011-dell-client-platform-security-update-for-a-bios-vulnerability vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.dell.com/support/kbdoc/en-us/000207928/dsa-2023-011-dell-client-platform-security-update-for-a-bios-vulnerability | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.