cbcvebase.
CVE-2023-28075
published 2023-08-16

CVE-2023-28075: Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially…

medium6.3CVSS 3.1
AVPACHPRLUINSUCHIHAH
Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.

Affected

243 ranges· showing 25
VendorProductVersion rangeFixed in
dellalienware_m15_r7_firmware< 1.18.01.18.0
dellalienware_m16_firmware< 1.10.11.10.1
dellalienware_m18_firmware< 1.10.11.10.1
dellchengming_3900_firmware< 1.15.01.15.0
dellchengming_3901_firmware< 1.15.01.15.0
dellchengming_3910_firmware< 1.6.01.6.0
dellchengming_3911_firmware< 1.6.01.6.0
dellchengming_3980_firmware< 2.32.02.32.0
dellchengming_3990_firmware< 1.21.01.21.0
dellchengming_3991_firmware< 1.21.01.21.0
dellcpg_bios
delledge_gateway_3000_firmware< 1.13.01.13.0
delledge_gateway_5000_firmware< 1.23.01.23.0
dellembedded_box_pc_3000_firmware< 1.19.01.19.0
dellembedded_box_pc_5000_firmware< 1.20.01.20.0
dellg15_5520_firmware< 1.18.01.18.0
dellg16_7620_firmware< 1.18.01.18.0
dellg3_3500_firmware< 1.26.01.26.0
dellg5_15_5500_firmware< 1.26.01.26.0
dellg5_15_5590_firmware< 1.26.01.26.0
dellg7_15_7500_firmware< 1.26.01.26.0
dellg7_15_7590_firmware< 1.26.01.26.0
dellg7_17_7700_firmware< 1.26.01.26.0
dellg7_17_7790_firmware< 1.26.01.26.0
dellinspiron_14_5410_firmware< 2.20.02.20.0