CVE-2022-34399
2.3
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Exploitability: 0.8 / Impact: 1.4
Source: NVD
Description
Dell Alienware m17 R5 BIOS version prior to 1.2.2 contain a buffer access vulnerability. A malicious user with admin privileges could potentially exploit this vulnerability by sending input larger than expected in order to leak certain sections of SMRAM.
Affected (15)
Products: Dell: Alienware M15 A6 Firmware, Alienware M15 Ryzen Edition R5 Firmware, Alienware M17 Ryzen Edition R5 Firmware, G15 5515 Firmware, G15 5525 Firmware, Inspiron 3505 Firmware, Inspiron 3515 Firmware, Inspiron 3525 Firmware, Inspiron 3585 Firmware, Inspiron 3595 Firmware, Inspiron 3785 Firmware, Vostro 3405 Firmware, Vostro 3425 Firmware, Vostro 3515 Firmware, Vostro 3525 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.3 |
| Running on/with | Platform Versions |
|---|---|
Dell Alienware M15 A6 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Alienware M15 Ryzen Edition R5 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.3 |
| Running on/with | Platform Versions |
|---|---|
Dell Alienware M17 Ryzen Edition R5 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.0 |
| Running on/with | Platform Versions |
|---|---|
Dell G15 5515 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.3 |
| Running on/with | Platform Versions |
|---|---|
Dell G15 5525 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.9.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 3505 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.9.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 3515 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.5.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 3525 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.10.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 3585 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.5.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 3595 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.10.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Inspiron 3785 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.9.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Vostro 3405 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.5.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Vostro 3425 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.9.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Vostro 3515 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.5.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Vostro 3525 | All versions |
Related CWEs
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-805
Buffer Access with Incorrect Length Value
The product uses a sequential operation to read or write a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer.
References (2)
Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.