VYPR

BIOS

by Dell

CVEs (117)

  • CVE-2020-5357HigMay 28, 2020
    risk 0.46cvss 7.1epss 0.00

    Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an…

  • CVE-2023-28075MedAug 16, 2023
    risk 0.45cvss 6.9epss 0.00

    Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code…

  • CVE-2022-22566MedFeb 9, 2022
    risk 0.45cvss 6.9epss 0.00

    Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.

  • CVE-2020-5388MedNov 10, 2020
    risk 0.45cvss 6.9epss 0.00

    Dell Inspiron 15 7579 2-in-1 BIOS versions prior to 1.31.0 contain an Improper SMM communication buffer verification vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

  • CVE-2024-0160MedJun 12, 2024
    risk 0.44cvss 6.8epss 0.00

    Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.

  • CVE-2023-48674MedMar 1, 2024
    risk 0.44cvss 6.8epss 0.00

    Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.

  • CVE-2023-28063MedFeb 6, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2023-39251MedDec 22, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability in order to corrupt memory on the system.

  • CVE-2023-32480MedJun 23, 2023
    risk 0.44cvss 6.8epss 0.00

    Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.

  • CVE-2022-24410MedFeb 10, 2023
    risk 0.44cvss 6.8epss 0.00

    Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces.

  • CVE-2022-29083MedAug 9, 2022
    risk 0.44cvss 6.8epss 0.00

    Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.

  • CVE-2020-26186MedJan 8, 2021
    risk 0.44cvss 6.8epss 0.00

    Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the RuntimeServices structure to execute arbitrary code in System Management…

  • CVE-2020-5379MedSep 2, 2020
    risk 0.44cvss 6.8epss 0.00

    Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management…

  • CVE-2020-5378MedSep 2, 2020
    risk 0.44cvss 6.8epss 0.00

    Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management…

  • CVE-2020-5376MedSep 2, 2020
    risk 0.44cvss 6.8epss 0.00

    Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management…

  • CVE-2020-5348MedApr 4, 2020
    risk 0.44cvss 6.8epss 0.00

    Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in…

  • CVE-2019-18579MedDec 16, 2019
    risk 0.44cvss 6.8epss 0.00

    Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for the "Enable Thunderbolt (and PCIe behind TBT) pre-boot modules" setting is enabled by default. A local unauthenticated attacker with physical…

  • CVE-2022-26864MedJun 23, 2022
    risk 0.41cvss 6.3epss 0.00

    Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.

  • CVE-2022-26863MedJun 23, 2022
    risk 0.41cvss 6.3epss 0.00

    Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.

  • CVE-2022-26862MedJun 23, 2022
    risk 0.41cvss 6.3epss 0.00

    Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.

Page 3 of 6