Dell Optiplex 7470 All-In-One Firmware vulnerabilities

47 known vulnerabilities affecting dell/optiplex_7470_all-in-one_firmware.

Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM34

Vulnerabilities

Page 3 of 3
CVE-2022-32484MEDIUMCVSS 4.4fixed in 1.16.02022-10-12
CVE-2022-32484 [MEDIUM] CWE-20 CVE-2022-32484: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2022-26859HIGHCVSS 7.0fixed in 1.12.02022-09-06
CVE-2022-26859 [HIGH] CWE-367 CVE-2022-26859: Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI in order to bypass security checks during SMM.
nvd
CVE-2022-26858HIGHCVSS 7.8fixed in 1.12.02022-09-06
CVE-2022-26858 [HIGH] CWE-287 CVE-2022-26858: Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicio Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls.
nvd
CVE-2022-26860HIGHCVSS 7.8fixed in 1.12.02022-09-06
CVE-2022-26860 [HIGH] CWE-121 CVE-2022-26860: Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could explo Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI to bypass security checks resulting in arbitrary code execution in SMM.
nvd
CVE-2022-26861HIGHCVSS 7.8fixed in 1.12.02022-09-06
CVE-2022-26861 [HIGH] CWE-1038 CVE-2022-26861: Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated m Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution during SMM.
nvd
CVE-2021-36342MEDIUMCVSS 6.4fixed in 1.11.02022-01-24
CVE-2021-36342 [MEDIUM] CWE-119 CVE-2021-36342: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
CVE-2021-36343MEDIUMCVSS 6.4fixed in 1.11.02022-01-24
CVE-2021-36343 [MEDIUM] CWE-119 CVE-2021-36343: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
nvd
Dell Optiplex 7470 All-In-One Firmware vulnerabilities | cvebase