cbcvebase.

Dell Cpg Bios vulnerabilities

110 known vulnerabilities affecting dell/cpg_bios.

Total CVEs
110
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH35MEDIUM70LOW5

Vulnerabilities

Page 5 of 6
CVE-2023-28033P4MEDIUMCVSS 6.7vAll Versions2023-06-23
CVE-2023-28033 [MEDIUM] CWE-20 CVE-2023-28033: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28026P4MEDIUMCVSS 6.7vAll Versions2023-06-23
CVE-2023-28026 [MEDIUM] CWE-20 CVE-2023-28026: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28029P4MEDIUMCVSS 6.7vAll Versions2023-06-23
CVE-2023-28029 [MEDIUM] CWE-20 CVE-2023-28029: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable
nvd
CVE-2023-25937P4MEDIUMCVSS 6.7vAll Versions2023-06-23
CVE-2023-25937 [MEDIUM] CWE-20 CVE-2023-25937: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2020-5388P4MEDIUMCVSS 6.9≥ unspecified, < 1.31.02020-11-10
CVE-2020-5388 [MEDIUM] CWE-119 CVE-2020-5388: Dell Inspiron 15 7579 2-in-1 BIOS versions prior to 1.31.0 contain an Improper SMM communication buf Dell Inspiron 15 7579 2-in-1 BIOS versions prior to 1.31.0 contain an Improper SMM communication buffer verification vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2024-32856P4MEDIUMCVSS 6.0≥ N/A, < 2.8.0≥ N/A, < 1.0.24+7 more2024-06-13
CVE-2024-32856 [MEDIUM] CWE-20 CVE-2024-32856: Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally devel Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2022-22567P4MEDIUMCVSS 5.1≥ unspecified, < 1.152022-02-09
CVE-2022-22567 [MEDIUM] CWE-345 CVE-2022-22567: Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware.
nvd
CVE-2023-48674P4MEDIUMCVSS 4.9≥ N/A, < 1.28.0≥ N/A, < 1.27.1+10 more2024-03-01
CVE-2023-48674 [MEDIUM] CWE-170 CVE-2023-48674: Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with n Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.
nvd
CVE-2022-32482P4MEDIUMCVSS 5.1≤ 2.15.22023-02-01
CVE-2022-32482 [MEDIUM] CWE-20 CVE-2022-32482: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2022-31225P4MEDIUMCVSS 5.1≥ unspecified, < 21Q4 platforms2022-09-12
CVE-2022-31225 [MEDIUM] CWE-252 CVE-2022-31225: Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administra Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures.
nvd
CVE-2022-31220P4MEDIUMCVSS 5.1≥ unspecified, < 21Q4 platforms2022-09-12
CVE-2022-31220 [MEDIUM] CWE-1038 CVE-2022-31220: Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administra Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures.
nvd
CVE-2021-36284P4MEDIUMCVSS 4.4≥ unspecified, < 1.7.02021-09-28
CVE-2021-36284 [MEDIUM] CWE-307 CVE-2021-36284: Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A loc Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive admin password attempt mitigations in order to carry out a brute force attack.
nvd
CVE-2021-36285P4MEDIUMCVSS 4.4≥ unspecified, < 1.7.02021-09-28
CVE-2021-36285 [MEDIUM] CWE-307 CVE-2021-36285: Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A loc Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt mitigations in order to carry out a brute force attack.
nvd
CVE-2021-21522P4MEDIUMCVSS 4.4≥ unspecified, < 1.13.02021-09-28
CVE-2021-21522 [MEDIUM] CWE-255 CVE-2021-21522: Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentia Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.
nvd
CVE-2024-32855P4MEDIUMCVSS 4.4≥ N/A, < 1.30.0≥ N/A, < 1.26.0+14 more2024-06-25
CVE-2024-32855 [MEDIUM] CWE-787 CVE-2024-32855: Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed c Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
nvd
CVE-2022-24410P4MEDIUMCVSS 4.2vAll supported versions2023-02-10
CVE-2022-24410 [MEDIUM] CWE-200 CVE-2022-24410: Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with ph Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces.
nvd
CVE-2022-32483P4MEDIUMCVSS 4.4≥ unspecified, < 2.3.12022-10-12
CVE-2022-32483 [MEDIUM] CWE-20 CVE-2022-32483: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2022-32484P4MEDIUMCVSS 4.4≥ unspecified, < 2.32022-10-12
CVE-2022-32484 [MEDIUM] CWE-20 CVE-2022-32484: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2024-28970P4MEDIUMCVSS 4.4≥ N/A, < 1.32.0≥ N/A, < 1.6.0+4 more2024-06-12
CVE-2024-28970 [MEDIUM] CWE-787 CVE-2024-28970: Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial of service.
nvd
CVE-2022-46752P4MEDIUMCVSS 4.6v1.8.0v1.19.0+25 more2023-03-08
CVE-2022-46752 [MEDIUM] CWE-285 CVE-2022-46752: Dell BIOS contains an Improper Authorization vulnerability. An unauthenticated physical attacker ma Dell BIOS contains an Improper Authorization vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability, leading to denial of service.
nvd