Dell Cpg Bios vulnerabilities
110 known vulnerabilities affecting dell/cpg_bios.
Total CVEs
110
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH35MEDIUM70LOW5
Vulnerabilities
Page 3 of 6
CVE-2022-24418P4MEDIUMCVSS 6.7≥ unspecified, < 1.10.02022-05-26
CVE-2022-24418 [MEDIUM] CWE-20 CVE-2022-24418: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
nvd
CVE-2021-36325P4MEDIUMCVSS 6.7≥ unspecified, < 1.13.02021-11-12
CVE-2021-36325 [MEDIUM] CWE-20 CVE-2021-36325: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2021-36323P4MEDIUMCVSS 6.7≥ unspecified, < 1.13.02021-11-12
CVE-2021-36323 [MEDIUM] CWE-20 CVE-2021-36323: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2021-36324P4MEDIUMCVSS 6.7≥ unspecified, < 1.13.02021-11-12
CVE-2021-36324 [MEDIUM] CWE-20 CVE-2021-36324: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2024-22429P4MEDIUMCVSS 6.7≥ N/A, < 2.36.0≥ N/A, < 1.18.0+8 more2024-05-17
CVE-2024-22429 [MEDIUM] CWE-20 CVE-2024-22429: Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.
nvd
CVE-2019-18579P4MEDIUMCVSS 6.8≥ unspecified, < 1.1.32019-12-16
CVE-2019-18579 [MEDIUM] CWE-16 CVE-2019-18579: Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vuln
Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for the "Enable Thunderbolt (and PCIe behind TBT) pre-boot modules" setting is enabled by default. A local unauthenticated attacker with physical access to a user's system can obtain read or write access to main memory
nvd
CVE-2024-0160P4MEDIUMCVSS 6.8≥ N/A, < 1.32.02024-06-12
CVE-2024-0160 [MEDIUM] CWE-863 CVE-2024-0160: Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical ac
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.
nvd
CVE-2021-36342P4MEDIUMCVSS 6.4≥ unspecified, < 1.142022-01-24
CVE-2021-36342 [MEDIUM] CWE-119 CVE-2021-36342: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2021-36343P4MEDIUMCVSS 6.4≥ unspecified, < 1.142022-01-24
CVE-2021-36343 [MEDIUM] CWE-119 CVE-2021-36343: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2020-5379P4MEDIUMCVSS 6.8≥ unspecified, < A122020-09-02
CVE-2020-5379 [MEDIUM] CWE-693 CVE-2020-5379: Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerabil
Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).
nvd
CVE-2020-5378P4MEDIUMCVSS 6.8≥ unspecified, < 1.13.02020-09-02
CVE-2020-5378 [MEDIUM] CWE-416 CVE-2020-5378: Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerabil
Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).
nvd
CVE-2020-5376P4MEDIUMCVSS 6.8≥ unspecified, < A132020-09-02
CVE-2020-5376 [MEDIUM] CWE-416 CVE-2020-5376: Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerabil
Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).
nvd
CVE-2020-26186P4MEDIUMCVSS 6.8≥ unspecified, < 1.4.12021-01-08
CVE-2020-26186 [MEDIUM] CWE-642 CVE-2020-26186: Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulner
Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the RuntimeServices structure to execute arbitrary code in System Management Mode (SMM).
nvd
CVE-2023-39251P4MEDIUMCVSS 6.7vVersions prior to 1.20.0vVersions prior to 1.23.0+3 more2023-12-22
CVE-2023-39251 [MEDIUM] CWE-20 CVE-2023-39251: Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high pri
Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability in order to corrupt memory on the system.
nvd
CVE-2024-0158P4MEDIUMCVSS 6.7≥ N/A, < 1.28.0≥ N/A, < 1.23.0+66 more2024-07-02
CVE-2024-0158 [MEDIUM] CWE-20 CVE-2024-0158: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
nvd
CVE-2023-28075P4MEDIUMCVSS 6.3vAll Versions2023-08-16
CVE-2023-28075 [MEDIUM] CWE-367 CVE-2023-28075: Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated maliciou
Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.
nvd
CVE-2020-5357P4MEDIUMCVSS 6.0≥ unspecified, < 1.0.82020-05-28
CVE-2020-5357 [MEDIUM] CWE-427 CVE-2020-5357: Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain
Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged maliciou
nvd
CVE-2023-28036P4MEDIUMCVSS 6.7vAll Versions2023-06-23
CVE-2023-28036 [MEDIUM] CWE-20 CVE-2023-28036: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-25938P4MEDIUMCVSS 6.7vAll Versions2023-06-23
CVE-2023-25938 [MEDIUM] CWE-20 CVE-2023-25938: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28039P4MEDIUMCVSS 6.7vAll Versions2023-06-23
CVE-2023-28039 [MEDIUM] CWE-20 CVE-2023-28039: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd