Dell Cpg Bios vulnerabilities
110 known vulnerabilities affecting dell/cpg_bios.
Total CVEs
110
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH35MEDIUM70LOW5
Vulnerabilities
Page 1 of 6
CVE-2022-34403P3HIGHCVSS 8.8≤ 2.15.22023-02-01
CVE-2022-34403 [HIGH] CWE-121 CVE-2022-34403: Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker coul
Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32492P3HIGHCVSS 8.8≥ unspecified, < 2.21.02022-10-11
CVE-2022-32492 [HIGH] CWE-20 CVE-2022-32492: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32486P3HIGHCVSS 8.8≥ unspecified, < 2.25.02022-10-11
CVE-2022-32486 [HIGH] CWE-20 CVE-2022-32486: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-26860P3HIGHCVSS 7.8≥ unspecified, < All2022-09-06
CVE-2022-26860 [HIGH] CWE-121 CVE-2022-26860: Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could explo
Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI to bypass security checks resulting in arbitrary code execution in SMM.
nvd
CVE-2022-31226P3HIGHCVSS 7.8≥ unspecified, < 21Q4 platforms2022-09-12
CVE-2022-31226 [HIGH] CWE-121 CVE-2022-31226: Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malici
Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could potentially exploit this vulnerability by sending excess data to a function in order to gain arbitrary code execution on the system.
nvd
CVE-2023-28073P3HIGHCVSS 7.8v 1.13.22023-06-23
CVE-2023-28073 [HIGH] CWE-287 CVE-2023-28073: Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user
Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user may potentially exploit this vulnerability by bypassing certain authentication mechanisms in order to elevate privileges on the system.
nvd
CVE-2020-5348P3HIGHCVSS 7.8≥ unspecified, < A282020-04-04
CVE-2020-5348 [HIGH] CWE-416 CVE-2020-5348: Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_
Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode.
nvd
CVE-2022-26862P3HIGHCVSS 7.8≥ unspecified, < 1.5.02022-06-23
CVE-2022-26862 [HIGH] CWE-20 CVE-2022-26862: Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated maliciou
Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.
nvd
CVE-2022-26863P3HIGHCVSS 7.8≥ unspecified, < 1.5.02022-06-23
CVE-2022-26863 [HIGH] CWE-20 CVE-2022-26863: Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated maliciou
Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.
nvd
CVE-2022-26864P3HIGHCVSS 7.8≥ unspecified, < 1.5.02022-06-23
CVE-2022-26864 [HIGH] CWE-20 CVE-2022-26864: Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated maliciou
Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.
nvd
CVE-2022-34391P3HIGHCVSS 7.8≥ unspecified, < 1.2.152022-10-12
CVE-2022-34391 [HIGH] CWE-119 CVE-2022-34391: Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulne
Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-26858P3HIGHCVSS 7.8≥ unspecified, < All2022-09-06
CVE-2022-26858 [HIGH] CWE-287 CVE-2022-26858: Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicio
Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls.
nvd
CVE-2022-24416P3HIGHCVSS 7.8≥ unspecified, < 1.162022-03-11
CVE-2022-24416 [HIGH] CWE-119 CVE-2022-24416: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2022-24420P3HIGHCVSS 7.8≥ unspecified, < 1.162022-03-11
CVE-2022-24420 [HIGH] CWE-119 CVE-2022-24420: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2022-24421P3HIGHCVSS 7.8≥ unspecified, < 1.162022-03-11
CVE-2022-24421 [HIGH] CWE-119 CVE-2022-24421: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2022-24419P3HIGHCVSS 7.8≥ unspecified, < 1.162022-03-11
CVE-2022-24419 [HIGH] CWE-119 CVE-2022-24419: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2022-24415P3HIGHCVSS 7.8≥ unspecified, < 1.162022-03-11
CVE-2022-24415 [HIGH] CWE-119 CVE-2022-24415: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2022-32489P3HIGHCVSS 7.8≥ unspecified, < OptiPlex 7770 All-In-One BIOS2022-10-12
CVE-2022-32489 [HIGH] CWE-20 CVE-2022-32489: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32488P3HIGHCVSS 7.8≥ unspecified, < OptiPlex 7770 All-In-One BIOS2022-10-12
CVE-2022-32488 [HIGH] CWE-20 CVE-2022-32488: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32485P3HIGHCVSS 7.8≥ unspecified, < 2.32022-10-12
CVE-2022-32485 [HIGH] CWE-20 CVE-2022-32485: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
1 / 6Next →