Dell Precision 5520 Firmware vulnerabilities

46 known vulnerabilities affecting dell/precision_5520_firmware.

Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM41

Vulnerabilities

Page 1 of 3
CVE-2024-38483MEDIUMCVSS 6.7fixed in 1.39.02024-08-14
CVE-2024-38483 [MEDIUM] CWE-20 CVE-2024-38483: Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2024-0158MEDIUMCVSS 6.7fixed in 1.37.02024-07-02
CVE-2024-0158 [MEDIUM] CWE-20 CVE-2024-0158: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
nvd
CVE-2024-22429MEDIUMCVSS 6.7fixed in 1.38.02024-05-17
CVE-2024-22429 [HIGH] CWE-20 CVE-2024-22429: Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.
nvd
CVE-2023-48674MEDIUMCVSS 4.9fixed in 1.36.02024-03-01
CVE-2023-48674 [MEDIUM] CWE-170 CVE-2023-48674: Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with n Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.
nvd
CVE-2023-28075MEDIUMCVSS 6.3fixed in 1.33.02023-08-16
CVE-2023-28075 [MEDIUM] CWE-367 CVE-2023-28075: Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated maliciou Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.
nvd
CVE-2023-25938MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-25938 [MEDIUM] CWE-20 CVE-2023-25938: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28039MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28039 [MEDIUM] CWE-20 CVE-2023-28039: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28050MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28050 [MEDIUM] CWE-20 CVE-2023-28050: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28042MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28042 [MEDIUM] CWE-20 CVE-2023-28042: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28061MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28061 [MEDIUM] CWE-20 CVE-2023-28061: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28028MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28028 [MEDIUM] CWE-20 CVE-2023-28028: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28030MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28030 [MEDIUM] CWE-20 CVE-2023-28030: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28027MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28027 [MEDIUM] CWE-20 CVE-2023-28027: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-25936MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-25936 [MEDIUM] CWE-20 CVE-2023-25936: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28054MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28054 [MEDIUM] CWE-20 CVE-2023-28054: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28041MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28041 [MEDIUM] CWE-20 CVE-2023-28041: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28036MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28036 [MEDIUM] CWE-20 CVE-2023-28036: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28060MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28060 [MEDIUM] CWE-20 CVE-2023-28060: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28032MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28032 [MEDIUM] CWE-20 CVE-2023-28032: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd
CVE-2023-28052MEDIUMCVSS 6.7fixed in 1.32.02023-06-23
CVE-2023-28052 [MEDIUM] CWE-20 CVE-2023-28052: Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
nvd