Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system.





Advisories
Source ID Title
EUVD EUVD EUVD-2022-37353 Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 26 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell latitude 3480
Dell latitude 3580
CPEs cpe:2.3:h:dell:dell_latitude_3480:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dell_latitude_3580:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3480:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3580:-:*:*:*:*:*:*:*
Vendors & Products Dell dell Latitude 3480
Dell dell Latitude 3580
Dell latitude 3480
Dell latitude 3580

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2025-03-26T18:53:45.169Z

Reserved: 2022-06-23T18:55:17.097Z

Link: CVE-2022-34398

cve-icon Vulnrichment

Updated: 2024-08-03T09:07:16.315Z

cve-icon NVD

Status : Modified

Published: 2023-02-01T06:15:08.710

Modified: 2024-12-19T14:25:44.370

Link: CVE-2022-34398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.