Description

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.





Published: 2023-01-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-37348 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
History

Thu, 03 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Dell G5 Se 5505 G5 Se 5505 Firmware Inspiron 27 7775 Inspiron 27 7775 Firmware Inspiron 3180 Inspiron 3180 Firmware Inspiron 3185 Inspiron 3185 Firmware Inspiron 3195 2-in-1 Inspiron 3195 2-in-1 Firmware Inspiron 3275 Inspiron 3275 Firmware Inspiron 3475 Inspiron 3475 Firmware Inspiron 3505 Inspiron 3505 Firmware Inspiron 3515 Inspiron 3515 Firmware Inspiron 3585 Inspiron 3585 Firmware Inspiron 3595 Inspiron 3595 Firmware Inspiron 3785 Inspiron 3785 Firmware Inspiron 5405 Inspiron 5405 Firmware Inspiron 5415 Inspiron 5415 Firmware Inspiron 5485 Inspiron 5485 2-in-1 Inspiron 5485 2-in-1 Firmware Inspiron 5485 Firmware Inspiron 5505 Inspiron 5505 Firmware Inspiron 5515 Inspiron 5515 Firmware Inspiron 5585 Inspiron 5585 Firmware Inspiron 7375 Inspiron 7375 Firmware Inspiron 7405 2-in-1 Inspiron 7405 2-in-1 Firmware Inspiron 7415 Inspiron 7415 Firmware Vostro 3405 Vostro 3405 Firmware Vostro 3515 Vostro 3515 Firmware Vostro 5415 Vostro 5415 Firmware Vostro 5515 Vostro 5515 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2025-04-03T19:38:19.876Z

Reserved: 2022-06-23T18:55:17.093Z

Link: CVE-2022-34393

cve-icon Vulnrichment

Updated: 2024-08-03T09:07:16.287Z

cve-icon NVD

Status : Modified

Published: 2023-01-18T06:15:11.413

Modified: 2024-11-21T07:09:25.563

Link: CVE-2022-34393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses