Dell Optiplex 5070 Firmware vulnerabilities

51 known vulnerabilities affecting dell/optiplex_5070_firmware.

Total CVEs
51
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM38

Vulnerabilities

Page 2 of 3
CVE-2023-28034MEDIUMCVSS 6.7fixed in 1.21.02023-06-23
CVE-2023-28034 [MEDIUM] CWE-20 CVE-2023-28034: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28031MEDIUMCVSS 6.7fixed in 1.21.02023-06-23
CVE-2023-28031 [MEDIUM] CWE-20 CVE-2023-28031: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28044MEDIUMCVSS 6.7fixed in 1.21.02023-06-23
CVE-2023-28044 [MEDIUM] CWE-20 CVE-2023-28044: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28056MEDIUMCVSS 6.7fixed in 1.21.02023-06-23
CVE-2023-28056 [MEDIUM] CWE-20 CVE-2023-28056: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28040MEDIUMCVSS 6.7fixed in 1.21.02023-06-23
CVE-2023-28040 [MEDIUM] CWE-20 CVE-2023-28040: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28035MEDIUMCVSS 6.7fixed in 1.21.02023-06-23
CVE-2023-28035 [MEDIUM] CWE-20 CVE-2023-28035: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28033MEDIUMCVSS 6.7fixed in 1.21.02023-06-23
CVE-2023-28033 [MEDIUM] CWE-20 CVE-2023-28033: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28026MEDIUMCVSS 6.7fixed in 1.21.02023-06-23
CVE-2023-28026 [MEDIUM] CWE-20 CVE-2023-28026: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28029MEDIUMCVSS 6.7fixed in 1.21.02023-06-23
CVE-2023-28029 [MEDIUM] CWE-20 CVE-2023-28029: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable
nvd
CVE-2023-25937MEDIUMCVSS 6.7fixed in 1.21.02023-06-23
CVE-2023-25937 [MEDIUM] CWE-20 CVE-2023-25937: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2022-34398HIGHCVSS 7.0fixed in 1.19.02023-02-01
CVE-2022-34398 [HIGH] CWE-367 CVE-2022-34398: Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system.
nvd
CVE-2022-32489HIGHCVSS 7.8fixed in 1.16.02022-10-12
CVE-2022-32489 [HIGH] CWE-20 CVE-2022-32489: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32491HIGHCVSS 7.8fixed in 1.16.02022-10-12
CVE-2022-32491 [MEDIUM] CWE-119 CVE-2022-32491: Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM.
nvd
CVE-2022-32485HIGHCVSS 7.8fixed in 1.16.02022-10-12
CVE-2022-32485 [HIGH] CWE-20 CVE-2022-32485: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32488HIGHCVSS 7.8fixed in 1.16.02022-10-12
CVE-2022-32488 [HIGH] CWE-20 CVE-2022-32488: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32487HIGHCVSS 7.8fixed in 1.16.02022-10-12
CVE-2022-32487 [HIGH] CWE-20 CVE-2022-32487: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32493HIGHCVSS 7.8fixed in 1.16.02022-10-12
CVE-2022-32493 [MEDIUM] CWE-121 CVE-2022-32493: Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious use Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2022-32483MEDIUMCVSS 4.4fixed in 1.16.02022-10-12
CVE-2022-32483 [MEDIUM] CWE-20 CVE-2022-32483: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2022-32484MEDIUMCVSS 4.4fixed in 1.16.02022-10-12
CVE-2022-32484 [MEDIUM] CWE-20 CVE-2022-32484: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2022-26859HIGHCVSS 7.0fixed in 1.12.02022-09-06
CVE-2022-26859 [MEDIUM] CWE-367 CVE-2022-26859: Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI in order to bypass security checks during SMM.
nvd
Dell Optiplex 5070 Firmware vulnerabilities | cvebase