![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-26859
https://notcve.org/view.php?id=CVE-2022-26859
06 Sep 2022 — Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending malicious input via SMI in order to bypass security checks during SMM. Dell BIOS contiene una vulnerabilidad de condición de carrera. Un atacante local podría explotar esta vulnerabilidad mediante el envío de entradas maliciosas por medio de SMI para omitir las comprobaciones de seguridad durante el SMM. • https://www.dell.com/support/kbdoc/000202194 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-26858
https://notcve.org/view.php?id=CVE-2022-26858
06 Sep 2022 — Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls. Las versiones de Dell BIOS contienen una vulnerabilidad de autenticación inapropiada. Un usuario malicioso autenticado localmente podría explotar esta vulnerabilidad mediante el envío de entradas maliciosas a un SMI con el fin de omitir los controles de seguridad. • https://www.dell.com/support/kbdoc/000202194 • CWE-287: Improper Authentication •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-29083
https://notcve.org/view.php?id=CVE-2022-29083
09 Aug 2022 — Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system. Las versiones anteriores de Dell BIOS contienen una vulnerabilidad de Autenticación Inapropiada. Un atacante no autenticado con acceso físico al sistema podría explotar esta vulnerabilidad al omitir los mecanismos de seguridad de la unidad para conseg... • https://www.dell.com/support/kbdoc/000201396 • CWE-287: Improper Authentication •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-22567
https://notcve.org/view.php?id=CVE-2022-22567
09 Feb 2022 — Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware. Algunas plataformas Dell Client Commercial y Consumer son vulnerables a una vulnerabilidad de verificación insuficiente de la autenticidad de los datos. Un usuario malicioso autenticado puede aprovechar esta vulnerabilidad para instalar un firmware de BIOS modificado • https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028 • CWE-345: Insufficient Verification of Data Authenticity •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-22566
https://notcve.org/view.php?id=CVE-2022-22566
09 Feb 2022 — Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device. Algunas plataformas Dell Client Commercial y Consumer contienen una vulnerabilidad de acceso directo a la memoria (DMA) antes del arranque. Un atacante autenticado con acceso físico al sistema podría explotar esta vulnerabilidad para ejecutar c... • https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028 • CWE-1190: DMA Device Enabled Too Early in Boot Phase •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-36325
https://notcve.org/view.php?id=CVE-2021-36325
12 Nov 2021 — Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. Dell BIOS contiene una vulnerabilidad de comprobación de entrada inapropiada. Un usuario malicioso autenticado localmente puede explotar potencialmente esta vulnerabilidad utilizando un SMI para conseguir una ejecución de código arbitrario en la SMRAM • https://www.dell.com/support/kbdoc/en-us/000192967 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-36324
https://notcve.org/view.php?id=CVE-2021-36324
12 Nov 2021 — Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. Dell BIOS contiene una vulnerabilidad de comprobación de entrada inapropiada. Un usuario malicioso autenticado localmente puede explotar potencialmente esta vulnerabilidad utilizando una SMI para conseguir una ejecución de código arbitrario en la SMRAM • https://www.dell.com/support/kbdoc/en-us/000192967 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-36323
https://notcve.org/view.php?id=CVE-2021-36323
12 Nov 2021 — Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. Dell BIOS contiene una vulnerabilidad de comprobación de entrada inapropiada. Un usuario malicioso autenticado localmente puede explotar potencialmente esta vulnerabilidad al usar una SMI para conseguir una ejecución de código arbitrario en la SMRAM • https://www.dell.com/support/kbdoc/en-us/000192967 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5362
https://notcve.org/view.php?id=CVE-2020-5362
10 Jun 2020 — Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values. Plataformas Dell Client Consumer and Commercial, incluyen una vulnerabilidad de autorización inapropiada en la interfaz de Administración de Dell para la cual un actor no autorizado, c... • https://www.dell.com/support/article/SLN321726 • CWE-285: Improper Authorization CWE-862: Missing Authorization •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-5326
https://notcve.org/view.php?id=CVE-2020-5326
21 Feb 2020 — Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring the BIOS Admin password by selecting the Optimized Defaults option in the pre-boot iRST Manager. Las plataformas afectadas de Dell Client contienen una vulnerabilidad de omisión de autenticaci... • https://www.dell.com/support/article/SLN320337 • CWE-306: Missing Authentication for Critical Function •