PT-2023-9249 · Dell · Dell Edge Gateway Bios

CVE-2023-32472

·

Published

2023-06-14

·

Updated

2024-09-26

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Edge Gateway BIOS versions 3200 and 5200
Description The issue is related to an out-of-bounds write vulnerability in the System Management Mode (SMM) of the BIOS firmware. This could be exploited by a local authenticated malicious user with high privileges, potentially leading to arbitrary code execution or escalation of privilege. The vulnerability is associated with incorrect initialization of a resource.
Recommendations For versions 3200 and 5200, update the BIOS to a version that fixes the out-of-bounds write vulnerability. As a temporary workaround, consider restricting access to the System Management Mode to minimize the risk of exploitation.

Fix

Memory Corruption

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05714
CVE-2023-32472

Affected Products

Dell Edge Gateway Bios