CVE-2022-31223

CWE-1583 documents3 sources
Severity
2.3LOW
EPSS
0.0%
top 85.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12
Latest updateSep 13

Description

Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read memory on the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:NExploitability: 0.8 | Impact: 1.4

Affected Packages26 packages

CVEListV5dell/cpg_biosunspecified21Q4 platforms

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2qf2-mq6q-w69h: Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability2022-09-13
CVEList
CVE-2022-31223: Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability2022-09-12
CVE-2022-31223 (LOW CVSS 2.3) | Dell BIOS versions contain an Impro | cvebase.io