// For flags

CVE-2022-34399

 

Severity Score

2.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Dell Alienware m17 R5 BIOS version prior to 1.2.2 contain a buffer access vulnerability. A malicious user with admin privileges could potentially exploit this vulnerability by sending input larger than expected in order to leak certain sections of SMRAM.

Las versiones de BIOS Dell Alienware m17 R5 anteriores a 1.2.2 contienen una vulnerabilidad de acceso al búfer. Un usuario malintencionado con privilegios de administrador podría explotar esta vulnerabilidad enviando entradas mayores a las esperadas para filtrar ciertas secciones de SMRAM.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-06-23 CVE Reserved
  • 2023-01-18 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-10 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  • CWE-805: Buffer Access with Incorrect Length Value
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dell
Search vendor "Dell"
Alienware M15 A6 Firmware
Search vendor "Dell" for product "Alienware M15 A6 Firmware"
< 1.4.3
Search vendor "Dell" for product "Alienware M15 A6 Firmware" and version " < 1.4.3"
-
Affected
in Dell
Search vendor "Dell"
Alienware M15 A6
Search vendor "Dell" for product "Alienware M15 A6"
--
Safe
Dell
Search vendor "Dell"
Alienware M15 Ryzen Edition R5 Firmware
Search vendor "Dell" for product "Alienware M15 Ryzen Edition R5 Firmware"
< 1.8.0
Search vendor "Dell" for product "Alienware M15 Ryzen Edition R5 Firmware" and version " < 1.8.0"
-
Affected
in Dell
Search vendor "Dell"
Alienware M15 Ryzen Edition R5
Search vendor "Dell" for product "Alienware M15 Ryzen Edition R5"
--
Safe
Dell
Search vendor "Dell"
Alienware M17 Ryzen Edition R5 Firmware
Search vendor "Dell" for product "Alienware M17 Ryzen Edition R5 Firmware"
< 1.4.3
Search vendor "Dell" for product "Alienware M17 Ryzen Edition R5 Firmware" and version " < 1.4.3"
-
Affected
in Dell
Search vendor "Dell"
Alienware M17 Ryzen Edition R5
Search vendor "Dell" for product "Alienware M17 Ryzen Edition R5"
--
Safe
Dell
Search vendor "Dell"
G15 5515 Firmware
Search vendor "Dell" for product "G15 5515 Firmware"
< 1.8.0
Search vendor "Dell" for product "G15 5515 Firmware" and version " < 1.8.0"
-
Affected
in Dell
Search vendor "Dell"
G15 5515
Search vendor "Dell" for product "G15 5515"
--
Safe
Dell
Search vendor "Dell"
G15 5525 Firmware
Search vendor "Dell" for product "G15 5525 Firmware"
< 1.4.3
Search vendor "Dell" for product "G15 5525 Firmware" and version " < 1.4.3"
-
Affected
in Dell
Search vendor "Dell"
G15 5525
Search vendor "Dell" for product "G15 5525"
--
Safe
Dell
Search vendor "Dell"
Inspiron 3505 Firmware
Search vendor "Dell" for product "Inspiron 3505 Firmware"
< 1.9.0
Search vendor "Dell" for product "Inspiron 3505 Firmware" and version " < 1.9.0"
-
Affected
in Dell
Search vendor "Dell"
Inspiron 3505
Search vendor "Dell" for product "Inspiron 3505"
--
Safe
Dell
Search vendor "Dell"
Inspiron 3515 Firmware
Search vendor "Dell" for product "Inspiron 3515 Firmware"
< 1.9.0
Search vendor "Dell" for product "Inspiron 3515 Firmware" and version " < 1.9.0"
-
Affected
in Dell
Search vendor "Dell"
Inspiron 3515
Search vendor "Dell" for product "Inspiron 3515"
--
Safe
Dell
Search vendor "Dell"
Inspiron 3525 Firmware
Search vendor "Dell" for product "Inspiron 3525 Firmware"
< 1.5.0
Search vendor "Dell" for product "Inspiron 3525 Firmware" and version " < 1.5.0"
-
Affected
in Dell
Search vendor "Dell"
Inspiron 3525
Search vendor "Dell" for product "Inspiron 3525"
--
Safe
Dell
Search vendor "Dell"
Inspiron 3585 Firmware
Search vendor "Dell" for product "Inspiron 3585 Firmware"
< 1.10.0
Search vendor "Dell" for product "Inspiron 3585 Firmware" and version " < 1.10.0"
-
Affected
in Dell
Search vendor "Dell"
Inspiron 3585
Search vendor "Dell" for product "Inspiron 3585"
--
Safe
Dell
Search vendor "Dell"
Inspiron 3595 Firmware
Search vendor "Dell" for product "Inspiron 3595 Firmware"
< 1.5.0
Search vendor "Dell" for product "Inspiron 3595 Firmware" and version " < 1.5.0"
-
Affected
in Dell
Search vendor "Dell"
Inspiron 3595
Search vendor "Dell" for product "Inspiron 3595"
--
Safe
Dell
Search vendor "Dell"
Inspiron 3785 Firmware
Search vendor "Dell" for product "Inspiron 3785 Firmware"
< 1.10.0
Search vendor "Dell" for product "Inspiron 3785 Firmware" and version " < 1.10.0"
-
Affected
in Dell
Search vendor "Dell"
Inspiron 3785
Search vendor "Dell" for product "Inspiron 3785"
--
Safe
Dell
Search vendor "Dell"
Vostro 3405 Firmware
Search vendor "Dell" for product "Vostro 3405 Firmware"
< 1.9.0
Search vendor "Dell" for product "Vostro 3405 Firmware" and version " < 1.9.0"
-
Affected
in Dell
Search vendor "Dell"
Vostro 3405
Search vendor "Dell" for product "Vostro 3405"
--
Safe
Dell
Search vendor "Dell"
Vostro 3425 Firmware
Search vendor "Dell" for product "Vostro 3425 Firmware"
< 1.5.0
Search vendor "Dell" for product "Vostro 3425 Firmware" and version " < 1.5.0"
-
Affected
in Dell
Search vendor "Dell"
Vostro 3425
Search vendor "Dell" for product "Vostro 3425"
--
Safe
Dell
Search vendor "Dell"
Vostro 3515 Firmware
Search vendor "Dell" for product "Vostro 3515 Firmware"
< 1.9.0
Search vendor "Dell" for product "Vostro 3515 Firmware" and version " < 1.9.0"
-
Affected
in Dell
Search vendor "Dell"
Vostro 3515
Search vendor "Dell" for product "Vostro 3515"
--
Safe
Dell
Search vendor "Dell"
Vostro 3525 Firmware
Search vendor "Dell" for product "Vostro 3525 Firmware"
< 1.5.0
Search vendor "Dell" for product "Vostro 3525 Firmware" and version " < 1.5.0"
-
Affected
in Dell
Search vendor "Dell"
Vostro 3525
Search vendor "Dell" for product "Vostro 3525"
--
Safe