Dell Inspiron 3195 2-In-1 Firmware vulnerabilities

4 known vulnerabilities affecting dell/inspiron_3195_2-in-1_firmware.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4

Vulnerabilities

Page 1 of 1
CVE-2022-34400HIGHCVSS 7.1fixed in 1.6.02023-02-01
CVE-2022-34400 [HIGH] CWE-122 CVE-2022-34400: Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges cou Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM.
nvd
CVE-2022-34403HIGHCVSS 8.8fixed in 1.6.02023-02-01
CVE-2022-34403 [HIGH] CWE-121 CVE-2022-34403: Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker coul Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-34393HIGHCVSS 7.5fixed in 1.5.02023-01-18
CVE-2022-34393 [HIGH] CWE-20 CVE-2022-34393: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-34460HIGHCVSS 7.8fixed in 1.5.02023-01-18
CVE-2022-34460 [HIGH] CWE-20 CVE-2022-34460: Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd