PT-2024-5327 · Dell · Dell Edge Gateway
Published
2024-05-09
·
Updated
2024-09-11
·
CVE-2023-32471
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dell Edge Gateway BIOS versions 3200 and 5200
Description
The issue is related to an out-of-bounds read vulnerability in the DXE driver of the BIOS firmware of Dell Edge Gateway devices. This vulnerability can be exploited by a local authenticated malicious user with high privileges to read the contents of stack memory, potentially using this information for further exploits.
Recommendations
For Dell Edge Gateway BIOS version 3200, update to a version that fixes the out-of-bounds read vulnerability.
For Dell Edge Gateway BIOS version 5200, update to a version that fixes the out-of-bounds read vulnerability.
As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation by a local authenticated malicious user.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Edge Gateway