cbcvebase.

Dell Alienware Aurora R11 Firmware vulnerabilities

46 known vulnerabilities affecting dell/alienware_aurora_r11_firmware.

Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH10MEDIUM36

Vulnerabilities

Page 1 of 3
CVE-2022-32489P3HIGHCVSS 7.8fixed in 1.0.162022-10-12
CVE-2022-32489 [HIGH] CWE-20 CVE-2022-32489: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32488P3HIGHCVSS 7.8fixed in 1.0.162022-10-12
CVE-2022-32488 [HIGH] CWE-20 CVE-2022-32488: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32485P3HIGHCVSS 7.8fixed in 1.0.162022-10-12
CVE-2022-32485 [HIGH] CWE-20 CVE-2022-32485: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32487P3HIGHCVSS 7.8fixed in 1.0.162022-10-12
CVE-2022-32487 [HIGH] CWE-20 CVE-2022-32487: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32493P3HIGHCVSS 7.8fixed in 1.0.162022-10-12
CVE-2022-32493 [HIGH] CWE-121 CVE-2022-32493: Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious use Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2024-32859P3HIGHCVSS 8.2fixed in 1.0.242024-06-13
CVE-2024-32859 [HIGH] CWE-20 CVE-2024-32859: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-32858P3HIGHCVSS 8.2fixed in 1.0.242024-06-13
CVE-2024-32858 [HIGH] CWE-20 CVE-2024-32858: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-32860P3HIGHCVSS 8.2fixed in 1.0.242024-06-13
CVE-2024-32860 [HIGH] CWE-20 CVE-2024-32860: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2022-32491P3HIGHCVSS 7.8fixed in 1.0.162022-10-12
CVE-2022-32491 [HIGH] CWE-119 CVE-2022-32491: Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM.
nvd
CVE-2022-34398P4HIGHCVSS 7.0fixed in 1.0.172023-02-01
CVE-2022-34398 [HIGH] CWE-367 CVE-2022-34398: Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system.
nvd
CVE-2021-36325P4MEDIUMCVSS 6.7fixed in 1.0.92021-11-12
CVE-2021-36325 [MEDIUM] CWE-20 CVE-2021-36325: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2021-36323P4MEDIUMCVSS 6.7fixed in 1.0.92021-11-12
CVE-2021-36323 [MEDIUM] CWE-20 CVE-2021-36323: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2021-36324P4MEDIUMCVSS 6.7fixed in 1.0.92021-11-12
CVE-2021-36324 [MEDIUM] CWE-20 CVE-2021-36324: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2021-36342P4MEDIUMCVSS 6.4fixed in 1.0.102022-01-24
CVE-2021-36342 [MEDIUM] CWE-119 CVE-2021-36342: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2021-36343P4MEDIUMCVSS 6.4fixed in 1.0.102022-01-24
CVE-2021-36343 [MEDIUM] CWE-119 CVE-2021-36343: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2023-28036P4MEDIUMCVSS 6.7fixed in 1.0.202023-06-23
CVE-2023-28036 [MEDIUM] CWE-20 CVE-2023-28036: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-25938P4MEDIUMCVSS 6.7fixed in 1.0.202023-06-23
CVE-2023-25938 [MEDIUM] CWE-20 CVE-2023-25938: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28039P4MEDIUMCVSS 6.7fixed in 1.0.202023-06-23
CVE-2023-28039 [MEDIUM] CWE-20 CVE-2023-28039: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28050P4MEDIUMCVSS 6.7fixed in 1.0.202023-06-23
CVE-2023-28050 [MEDIUM] CWE-20 CVE-2023-28050: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28042P4MEDIUMCVSS 6.7fixed in 1.0.202023-06-23
CVE-2023-28042 [MEDIUM] CWE-20 CVE-2023-28042: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
Dell Alienware Aurora R11 Firmware vulnerabilities | cvebase