cbcvebase.

Dell Cpg Bios vulnerabilities

110 known vulnerabilities affecting dell/cpg_bios.

Total CVEs
110
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH35MEDIUM70LOW5

Vulnerabilities

Page 2 of 6
CVE-2022-32487P3HIGHCVSS 7.8≥ unspecified, < 2.32022-10-12
CVE-2022-32487 [HIGH] CWE-20 CVE-2022-32487: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-26861P3HIGHCVSS 7.8≥ unspecified, < Gen7, Gen8, Gen9, Gen10, Gen11, 21Q1-Q42022-09-06
CVE-2022-26861 [HIGH] CWE-1038 CVE-2022-26861: Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated m Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution during SMM.
nvd
CVE-2022-32493P3HIGHCVSS 7.8≥ unspecified, < XPS 8940 BIOS (version: 2.5.1)2022-10-12
CVE-2022-32493 [HIGH] CWE-121 CVE-2022-32493: Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious use Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-34390P3HIGHCVSS 7.8≥ unspecified, < 8 MSI Platforms2022-10-12
CVE-2022-34390 [HIGH] CWE-457 CVE-2022-34390: Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious us Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2024-32859P3HIGHCVSS 8.2≥ N/A, < 2.8.0≥ N/A, < 1.0.24+8 more2024-06-13
CVE-2024-32859 [HIGH] CWE-20 CVE-2024-32859: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-32858P3HIGHCVSS 8.2≥ N/A, < 2.8.0≥ N/A, < 1.0.24+8 more2024-06-13
CVE-2024-32858 [HIGH] CWE-20 CVE-2024-32858: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-32860P3HIGHCVSS 8.2≥ N/A, < 1.0.24≥ N/A, < 1.1.25+7 more2024-06-13
CVE-2024-32860 [HIGH] CWE-20 CVE-2024-32860: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2022-32491P3HIGHCVSS 7.8≥ unspecified, < OptiPlex 7770 All-In-One BIOS (version: 1.14.0)2022-10-12
CVE-2022-32491 [HIGH] CWE-119 CVE-2022-32491: Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM.
nvd
CVE-2023-32475P3HIGHCVSS 7.6≥ N/A, < 2.6.0≥ N/A, < 1.13.0+11 more2024-06-07
CVE-2023-32475 [HIGH] CWE-353 CVE-2023-32475: Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical ac Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system.
nvd
CVE-2020-5361P3HIGHCVSS 7.6≥ unspecified, < All2021-01-04
CVE-2020-5361 [HIGH] CWE-640 CVE-2020-5361: Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that i Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. Dell is aware of unauthorized password generation tools that can generate BIOS recovery passwords. The tools, which are not authorized by Dell, can be used by a physically present attac
nvd
CVE-2022-34401P3HIGHCVSS 7.5v1.4.32023-01-18
CVE-2022-34401 [HIGH] CWE-121 CVE-2022-34401: Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious use Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-22566P4HIGHCVSS 7.2≥ unspecified, < 1.152022-02-09
CVE-2022-22566 [HIGH] CWE-1190 CVE-2022-22566: Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) v Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.
nvd
CVE-2022-34400P4HIGHCVSS 7.1≤ 2.15.22023-02-01
CVE-2022-34400 [HIGH] CWE-122 CVE-2022-34400: Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges cou Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM.
nvd
CVE-2022-34398P4HIGHCVSS 7.0≤ 2.15.02023-02-01
CVE-2022-34398 [HIGH] CWE-367 CVE-2022-34398: Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system.
nvd
CVE-2023-43088P4MEDIUMCVSS 6.8vVersions prior to 1.5.02023-12-22
CVE-2023-43088 [MEDIUM] CWE-16 CVE-2023-43088: Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability. An authenticated att Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.
nvd
CVE-2022-26859P4HIGHCVSS 7.0≥ unspecified, < All2022-09-06
CVE-2022-26859 [HIGH] CWE-367 CVE-2022-26859: Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI in order to bypass security checks during SMM.
nvd
CVE-2022-29083P4MEDIUMCVSS 6.8≥ unspecified, < 9-122022-08-09
CVE-2022-29083 [MEDIUM] CWE-287 CVE-2022-29083: Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attack Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.
nvd
CVE-2023-32480P4MEDIUMCVSS 6.8vAll Versions2023-06-23
CVE-2023-32480 [MEDIUM] CWE-20 CVE-2023-32480: Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.
nvd
CVE-2021-36283P4MEDIUMCVSS 6.7≥ unspecified, < 1.3.12021-09-28
CVE-2021-36283 [MEDIUM] CWE-20 CVE-2021-36283: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-24417P4MEDIUMCVSS 6.7≥ unspecified, < 1.10.02022-05-26
CVE-2022-24417 [MEDIUM] CWE-20 CVE-2022-24417: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
Dell Cpg Bios vulnerabilities | cvebase