Unrated severityNVD Advisory· Published Aug 28, 2013· Updated Apr 29, 2026
CVE-2013-3582
CVE-2013-3582
Description
Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.
Affected products
22- cpe:2.3:h:dell:latitude_d530:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_d531:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_d630:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_d631:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_d830:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_e4200:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_e4300:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_e5400:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_e5500:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_e6400:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_e6400_atg:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_e6400_atg_xfr:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_e6500:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_xt2:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:latitude_z600:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:precision_m2300:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:precision_m2400:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:precision_m4300:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:precision_m4400:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:precision_m6300:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:precision_m6400:-:*:*:*:*:*:*:*
- cpe:2.3:h:dell:precision_m6500:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- media.blackhat.com/us-13/US-13-Butterworth-BIOS-Security-Slides.pdfnvdExploit
- media.blackhat.com/us-13/US-13-Butterworth-BIOS-Security-WP.pdfnvdExploit
- www.kb.cert.org/vuls/id/912156nvdUS Government Resource
- www.kb.cert.org/vuls/id/BLUU-99HSLAnvdUS Government Resource
- www.blackhat.com/us-13/archives.htmlnvd
News mentions
0No linked articles in our index yet.