CVE-2022-26858
published 2022-09-06CVE-2022-26858: Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.1th percentile
Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls.
Affected
400 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | alienware_m15_r6_firmware | < 1.8.0 | 1.8.0 |
| dell | chengming_3980_firmware | < 2.21.0 | 2.21.0 |
| dell | chengming_3988_firmware | < 1.9.0 | 1.9.0 |
| dell | chengming_3990_firmware | < 1.8.2 | 1.8.2 |
| dell | chengming_3991_firmware | < 1.8.2 | 1.8.2 |
| dell | cpg_bios | >= unspecified < All | All |
| dell | edge_gateway_3000_firmware | < 1.8.0 | 1.8.0 |
| dell | edge_gateway_5000_firmware | < 1.18.0 | 1.18.0 |
| dell | embedded_box_pc_3000_firmware | < 1.14.0 | 1.14.0 |
| dell | embedded_box_pc_5000_firmware | < 1.15.0 | 1.15.0 |
| dell | g15_5510_firmware | < 1.8.0 | 1.8.0 |
| dell | g15_5511_firmware | < 1.9.0 | 1.9.0 |
| dell | g3_15_3590_firmware | < 1.16.0 | 1.16.0 |
| dell | g3_3500_firmware | < 1.12.0 | 1.12.0 |
| dell | g3_3579_firmware | < 1.19.0 | 1.19.0 |
| dell | g5_15_5587_firmware | < 1.19.0 | 1.19.0 |
| dell | g5_15_5590_firmware | < 1.18.0 | 1.18.0 |
| dell | g5_5000_firmware | < 1.5.1 | 1.5.1 |
| dell | g5_5090_firmware | < 1.12.0 | 1.12.0 |
| dell | g5_5500_firmware | < 1.12.0 | 1.12.0 |
| dell | g7_17_7700_firmware | < 1.12.0 | 1.12.0 |
| dell | g7_17_7790_firmware | < 1.18.0 | 1.18.0 |
| dell | g7_7500_firmware | < 1.12.0 | 1.12.0 |
| dell | g7_7588_firmware | < 1.19.0 | 1.19.0 |
| dell | inspiron_13_5378_firmware | < 1.36.0 | 1.36.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cisa7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r95r-f5pv-5rr9: Dell BIOS versions contain an Improper Authentication vulnerability
ghsa_unreviewed·2022-09-07
CVE-2022-26858 [HIGH] CWE-287 GHSA-r95r-f5pv-5rr9: Dell BIOS versions contain an Improper Authentication vulnerability
Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls.
CISA
Microsoft Exchange Server Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2021-26858 [HIGH] Microsoft Exchange Server Remote Code Execution Vulnerability
Vulnerability: Microsoft Exchange Server Remote Code Execution Vulnerability
Affected: Microsoft Exchange Server
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Required Action: Apply updates per vendor instructions.
Notes: Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26858
Remediation Due Date: 2022-05-03
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-06
Published