CVE-2022-34400
01.02.2023, 05:15
Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM.Enginsight
Vendor | Product | Version |
---|---|---|
dell | alienware_m15_r6_firmware | 𝑥 < 1.17.0 |
dell | alienware_m15_r7_firmware | 𝑥 < 1.4.3 |
dell | alienware_m15_ryzen_edition_r5_firmware | 𝑥 < 1.8.0 |
dell | alienware_m17_r5_amd_firmware | 𝑥 < 1.4.3 |
dell | g15_5510_firmware | 𝑥 < 1.16.0 |
dell | g15_5511_firmware | 𝑥 < 1.18.0 |
dell | g15_5515_firmware | 𝑥 < 1.8.0 |
dell | g15_5525_firmware | 𝑥 < 1.4.3 |
dell | g5_se_5505_firmware | 𝑥 < 1.13.0 |
dell | inspiron_14_5410_2-in-1_firmware | 𝑥 < 2.15.2 |
dell | inspiron_15_3511_firmware | 𝑥 < 1.18.2 |
dell | inspiron_3195_2-in-1_firmware | 𝑥 < 1.6.0 |
dell | inspiron_3275_firmware | 𝑥 < 1.9.2 |
dell | inspiron_3475_firmware | 𝑥 < 1.9.2 |
dell | inspiron_3505_firmware | 𝑥 < 1.9.0 |
dell | inspiron_3515_firmware | 𝑥 < 1.9.0 |
dell | inspiron_3525_firmware | 𝑥 < 1.5.0 |
dell | inspiron_3585_firmware | 𝑥 < 1.10.0 |
dell | inspiron_3595_firmware | 𝑥 < 1.5.0 |
dell | inspiron_3785_firmware | 𝑥 < 1.10.0 |
dell | inspiron_3891_firmware | 𝑥 < 1.12.0 |
dell | inspiron_5310_firmware | 𝑥 < 2.15.0 |
dell | inspiron_5405_firmware | 𝑥 < 1.9.0 |
dell | inspiron_5410_firmware | 𝑥 < 2.14.0 |
dell | inspiron_5415_firmware | 𝑥 < 1.13.0 |
dell | inspiron_5425_firmware | 𝑥 < 1.5.0 |
dell | inspiron_5485_firmware | 𝑥 < 2.11.0 |
dell | inspiron_5485_2-in-1_firmware | 𝑥 < 2.11.0 |
dell | inspiron_5505_firmware | 𝑥 < 1.9.0 |
dell | inspiron_5510_firmware | 𝑥 < 2.15.2 |
dell | inspiron_5515_firmware | 𝑥 < 1.13.0 |
dell | inspiron_5585_firmware | 𝑥 < 2.11.0 |
dell | inspiron_7405_2-in-1_firmware | 𝑥 < 1.10.1 |
dell | inspiron_7415_firmware | 𝑥 < 1.13.0 |
dell | inspiron_7425_firmware | 𝑥 < 1.5.0 |
dell | inspiron_7510_firmware | 𝑥 < 1.12.0 |
dell | inspiron_7610_firmware | 𝑥 < 1.12.0 |
dell | latitude_3320_firmware | 𝑥 < 1.18.2 |
dell | latitude_3420_firmware | 𝑥 < 1.23.2 |
dell | latitude_3520_firmware | 𝑥 < 1.23.2 |
dell | latitude_5320_firmware | 𝑥 < 1.24.3 |
dell | latitude_5420_firmware | 𝑥 < 1.22.0 |
dell | latitude_5520_firmware | 𝑥 < 1.24.3 |
dell | latitude_5521_firmware | 𝑥 < 1.17.3 |
dell | latitude_7320_firmware | 𝑥 < 1.20.0 |
dell | latitude_7320_detachable_firmware | 𝑥 < 1.17.2 |
dell | latitude_7420_firmware | 𝑥 < 1.20.0 |
dell | latitude_7520_firmware | 𝑥 < 1.20.0 |
dell | latitude_9420_firmware | 𝑥 < 1.16.2 |
dell | latitude_9520_firmware | 𝑥 < 1.17.0 |
dell | latitude_rugged_5430_firmware | 𝑥 < 1.12.0 |
dell | latitude_rugged_7330_firmware | 𝑥 < 1.12.0 |
dell | latitude_5421_firmware | 𝑥 < 1.15.0 |
dell | optiplex_5090_firmware | 𝑥 < 1.12.0 |
dell | optiplex_5490_all-in-one_firmware | 𝑥 < 1.15.0 |
dell | optiplex_7090_tower_firmware | 𝑥 < 1.12.0 |
dell | optiplex_7090_ultra_firmware | 𝑥 < 1.15.0 |
dell | optiplex_7090_aio_firmware | 𝑥 < 1.15.0 |
dell | precision_3450_firmware | 𝑥 < 1.12.0 |
dell | precision_3560_firmware | 𝑥 < 1.24.3 |
dell | precision_3561_firmware | 𝑥 < 1.17.3 |
dell | precision_3650_tower_firmware | 𝑥 < 1.16.0 |
dell | precision_5560_firmware | 𝑥 < 1.15.2 |
dell | precision_5760_firmware | 𝑥 < 1.15.2 |
dell | precision_7560_firmware | 𝑥 < 1.16.0 |
dell | precision_7760_firmware | 𝑥 < 1.16.0 |
dell | vostro_3405_firmware | 𝑥 < 1.9.0 |
dell | vostro_3425_firmware | 𝑥 < 1.5.0 |
dell | vostro_3510_firmware | 𝑥 < 1.18.2 |
dell | vostro_3515_firmware | 𝑥 < 1.9.0 |
dell | vostro_3525_firmware | 𝑥 < 1.5.0 |
dell | vostro_3690_firmware | 𝑥 < 1.12.0 |
dell | vostro_3890_firmware | 𝑥 < 1.12.0 |
dell | vostro_5310_firmware | 𝑥 < 2.15.0 |
dell | vostro_5410_firmware | 𝑥 < 2.15.2 |
dell | vostro_5415_firmware | 𝑥 < 1.13.0 |
dell | vostro_5510_firmware | 𝑥 < 2.15.2 |
dell | vostro_5515_firmware | 𝑥 < 1.13.0 |
dell | vostro_5625_firmware | 𝑥 < 1.5.0 |
dell | vostro_5890_firmware | 𝑥 < 1.12.0 |
dell | vostro_7510_firmware | 𝑥 < 1.12.0 |
dell | xps_15_9510_firmware | 𝑥 < 1.15.2 |
dell | xps_17_9710_firmware | 𝑥 < 1.15.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-122 - Heap-based Buffer OverflowA heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.