PT-2023-13395 · Dell · Dell Poweredge Bios+1

Published

2023-03-16

·

Updated

2023-03-22

·

CVE-2022-34417

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerEdge BIOS (affected versions not specified) Dell Precision BIOS (affected versions not specified)
Description The issue concerns an improper SMM communication buffer verification. A local malicious user with high privileges may potentially exploit this to perform arbitrary code execution or cause denial of service.
Recommendations For Dell PowerEdge BIOS, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Dell Precision BIOS, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-34417

Affected Products

Dell Poweredge Bios
Dell Precision Bios