CVE-2022-31222
12.09.2022, 19:15
Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by consuming excess memory in order to cause the application to crash.Enginsight
Vendor | Product | Version |
---|---|---|
dell | chengming_3900_firmware | 𝑥 < 1.1.66 |
dell | inspiron_14_plus_7420_firmware | 𝑥 < 1.2.0 |
dell | inspiron_16_plus_7620_firmware | 𝑥 < 1.2.0 |
dell | inspiron_3910_firmware | 𝑥 < 1.1.66 |
dell | inspiron_5320_firmware | 𝑥 < 1.1.0 |
dell | inspiron_5420_firmware | 𝑥 < 1.4.1 |
dell | inspiron_5620_firmware | 𝑥 < 1.4.1 |
dell | inspiron_7420_firmware | 𝑥 < 1.3.0 |
dell | inspiron_7620_firmware | 𝑥 < 1.3.0 |
dell | optiplex_3000_firmware | 𝑥 < 1.1.66 |
dell | optiplex_3000_thin_client_firmware | 𝑥 < 1.0.7 |
dell | optiplex_5000_firmware | 𝑥 < 1.3.62 |
dell | optiplex_5400_firmware | 𝑥 < 1.0.13 |
dell | optiplex_7000_firmware | 𝑥 < 1.3.62 |
dell | optiplex_7000_oem_firmware | 𝑥 < 1.3.62 |
dell | optiplex_7400_firmware | 𝑥 < 1.0.13 |
dell | precision_3460_small_form_factor_firmware | 𝑥 < 1.3.62 |
dell | precision_3660_tower_firmware | 𝑥 < 1.3.71 |
dell | precision_5770_firmware | 𝑥 < 1.6.0 |
dell | vostro_3710_firmware | 𝑥 < 1.1.66 |
dell | vostro_3910_firmware | 𝑥 < 1.1.66 |
dell | vostro_5320_firmware | 𝑥 < 1.1.0 |
dell | vostro_5620_firmware | 𝑥 < 1.4.1 |
dell | vostro_7620_firmware | 𝑥 < 1.2.0 |
dell | xps_17_9720_firmware | 𝑥 < 1.6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-401 - Missing Release of Memory after Effective LifetimeThe software does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
- CWE-772 - Missing Release of Resource after Effective LifetimeThe software does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.