Dell Alienware M15 R4 Firmware vulnerabilities
51 known vulnerabilities affecting dell/alienware_m15_r4_firmware.
Total CVEs
51
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH17MEDIUM34
Vulnerabilities
Page 1 of 3
CVE-2024-39584P3HIGHCVSS 8.2fixed in 1.24.02024-08-28
CVE-2024-39584 [HIGH] CWE-1392 CVE-2024-39584: Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privile
Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.
nvd
CVE-2022-24416P3HIGHCVSS 7.8fixed in 1.8.02022-03-11
CVE-2022-24416 [HIGH] CWE-119 CVE-2022-24416: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2022-24420P3HIGHCVSS 7.8fixed in 1.8.02022-03-11
CVE-2022-24420 [HIGH] CWE-119 CVE-2022-24420: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2022-24421P3HIGHCVSS 7.8fixed in 1.8.02022-03-11
CVE-2022-24421 [HIGH] CWE-119 CVE-2022-24421: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2022-24419P3HIGHCVSS 7.8fixed in 1.8.02022-03-11
CVE-2022-24419 [HIGH] CWE-119 CVE-2022-24419: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2022-24415P3HIGHCVSS 7.8fixed in 1.8.02022-03-11
CVE-2022-24415 [HIGH] CWE-119 CVE-2022-24415: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2022-32489P3HIGHCVSS 7.8fixed in 1.13.02022-10-12
CVE-2022-32489 [HIGH] CWE-20 CVE-2022-32489: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32488P3HIGHCVSS 7.8fixed in 1.13.02022-10-12
CVE-2022-32488 [HIGH] CWE-20 CVE-2022-32488: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32485P3HIGHCVSS 7.8fixed in 1.13.02022-10-12
CVE-2022-32485 [HIGH] CWE-20 CVE-2022-32485: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32487P3HIGHCVSS 7.8fixed in 1.13.02022-10-12
CVE-2022-32487 [HIGH] CWE-20 CVE-2022-32487: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32493P3HIGHCVSS 7.8fixed in 1.13.02022-10-12
CVE-2022-32493 [HIGH] CWE-121 CVE-2022-32493: Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious use
Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2024-32859P3HIGHCVSS 8.2fixed in 1.21.02024-06-13
CVE-2024-32859 [HIGH] CWE-20 CVE-2024-32859: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-32858P3HIGHCVSS 8.2fixed in 1.21.02024-06-13
CVE-2024-32858 [HIGH] CWE-20 CVE-2024-32858: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-32860P3HIGHCVSS 8.2≤ 1.21.02024-06-13
CVE-2024-32860 [HIGH] CWE-20 CVE-2024-32860: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2022-32491P3HIGHCVSS 7.8fixed in 1.13.02022-10-12
CVE-2022-32491 [HIGH] CWE-119 CVE-2022-32491: Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may
Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM.
nvd
CVE-2022-22566P4HIGHCVSS 7.2fixed in 1.6.22022-02-09
CVE-2022-22566 [HIGH] CWE-1190 CVE-2022-22566: Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) v
Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.
nvd
CVE-2022-34398P4HIGHCVSS 7.0fixed in 1.14.02023-02-01
CVE-2022-34398 [HIGH] CWE-367 CVE-2022-34398: Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user
Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system.
nvd
CVE-2021-36342P4MEDIUMCVSS 6.4fixed in 1.6.22022-01-24
CVE-2021-36342 [MEDIUM] CWE-119 CVE-2021-36342: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2021-36343P4MEDIUMCVSS 6.4fixed in 1.6.22022-01-24
CVE-2021-36343 [MEDIUM] CWE-119 CVE-2021-36343: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2023-28036P4MEDIUMCVSS 6.7fixed in 1.17.02023-06-23
CVE-2023-28036 [MEDIUM] CWE-20 CVE-2023-28036: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
1 / 3Next →