cbcvebase.
CVE-2022-34401
published 2023-01-18

CVE-2022-34401: Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI…

high7.5CVSS 3.1
AVLACHPRHUINSCCHIHAH
Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM.

Affected

4 ranges
VendorProductVersion rangeFixed in
dellalienware_m15_a6_firmware< 1.4.31.4.3
dellalienware_m17_r5_firmware< 1.4.31.4.3
dellcpg_bios
dellg15_5525_firmware< 1.4.31.4.3