CVE-2022-34410
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service.
Affected (80)
Products: Dell: R6515 Firmware, R7515 Firmware, R6525 Firmware, R7525 Firmware, Xe8545 Firmware, C6525 Firmware, R6415 Firmware, R7415 Firmware, R7425 Firmware, R750 Firmware, R750xa Firmware, R650 Firmware, C6520 Firmware, Mx750c Firmware, R450 Firmware, R550 Firmware, R650xs Firmware, R750xs Firmware, T550 Firmware, Xr11 Firmware, Xr12 Firmware, R250 Firmware, R350 Firmware, T150 Firmware, T350 Firmware, R740 Firmware, R740xd Firmware, R640 Firmware, R940 Firmware, R540 Firmware, R440 Firmware, T440 Firmware, Xr2 Firmware, R740xd2 Firmware, R840 Firmware, R940xa Firmware, T640 Firmware, C6420 Firmware, Fc640 Firmware, M640 Firmware, M640p Firmware, Mx740c Firmware, Mx840c Firmware, C4140 Firmware, Dss8440 Firmware, T140 Firmware, T340 Firmware, R240 Firmware, R340 Firmware, Xe2420 Firmware, Xe7420 Firmware, Xe7440 Firmware, R730 Firmware, R730xd Firmware, R630 Firmware, C4130 Firmware, R930 Firmware, M630 Firmware, M630p Firmware, Fc630 Firmware, Fc430 Firmware, M830 Firmware, M830p Firmware, Fc830 Firmware, T630 Firmware, R530 Firmware, R430 Firmware, T430 Firmware, R830 Firmware, C6320 Firmware, T130 Firmware, R230 Firmware, T330 Firmware, R330 Firmware, Nx430 Firmware, Nx3230 Firmware, Nx3330 Firmware, Nx440 Firmware, Nx3240 Firmware, Nx3340 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.9.3 |
| Running on/with | Platform Versions |
|---|---|
Dell R6515 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.9.3 |
| Running on/with | Platform Versions |
|---|---|
Dell R7515 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.9.3 |
| Running on/with | Platform Versions |
|---|---|
Dell R6525 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.9.3 |
| Running on/with | Platform Versions |
|---|---|
Dell R7525 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.9.4 |
| Running on/with | Platform Versions |
|---|---|
Dell Xe8545 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dell C6525 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.19.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R6415 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.19.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R7415 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.19.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R7425 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell R750 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell R750xa | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell R650 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell C6520 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Mx750c | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell R450 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell R550 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell R650xs | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell R750xs | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell T550 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Xr11 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8.2 |
| Running on/with | Platform Versions |
|---|---|
Dell Xr12 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Dell R250 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Dell R350 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Dell T150 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Dell T350 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R740 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R740xd | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R640 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R940 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R540 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R440 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell T440 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Xr2 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R740xd2 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R840 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R940xa | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell T640 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell C6420 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Fc640 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell M640 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell M640p | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Mx740c | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Mx840c | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell C4140 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Dss8440 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.11.1 |
| Running on/with | Platform Versions |
|---|---|
Dell T140 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.11.1 |
| Running on/with | Platform Versions |
|---|---|
Dell T340 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.11.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R240 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.11.1 |
| Running on/with | Platform Versions |
|---|---|
Dell R340 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Xe2420 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Xe7420 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Xe7440 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R730 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R730xd | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R630 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell C4130 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R930 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell M630 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell M630p | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Fc630 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Fc430 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell M830 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell M830p | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Fc830 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell T630 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R530 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R430 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell T430 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R830 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell C6320 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell T130 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R230 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell T330 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell R330 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Nx430 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Nx3230 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.0 |
| Running on/with | Platform Versions |
|---|---|
Dell Nx3330 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.11.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Nx440 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Nx3240 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.16.1 |
| Running on/with | Platform Versions |
|---|---|
Dell Nx3340 | All versions |
References (2)
Source: security_alert@emc.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.