Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dell
Dell chengming 3977 Dell chengming 3977 Firmware Dell edge Gateway 3200 Dell edge Gateway 3200 Firmware Dell edge Gateway 5000 Dell edge Gateway 5000 Firmware Dell edge Gateway 5100 Dell edge Gateway 5100 Firmware Dell edge Gateway 5200 Dell edge Gateway 5200 Firmware Dell xps 13 9350 Dell xps 13 9350 Firmware |
|
CPEs | cpe:2.3:h:dell:chengming_3977:-:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_3200:-:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_5000:-:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_5100:-:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_5200:-:*:*:*:*:*:*:* cpe:2.3:h:dell:xps_13_9350:-:*:*:*:*:*:*:* cpe:2.3:o:dell:chengming_3977_firmware:0.1.13.0:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_3200_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_5000_firmware:0.1.19.0:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_5100_firmware:0.1.19.0:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_5200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dell:xps_13_9350_firmware:0.1.13.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Dell
Dell chengming 3977 Dell chengming 3977 Firmware Dell edge Gateway 3200 Dell edge Gateway 3200 Firmware Dell edge Gateway 5000 Dell edge Gateway 5000 Firmware Dell edge Gateway 5100 Dell edge Gateway 5100 Firmware Dell edge Gateway 5200 Dell edge Gateway 5200 Firmware Dell xps 13 9350 Dell xps 13 9350 Firmware |
MITRE
Status: PUBLISHED
Assigner: dell
Published: 2024-07-10T02:39:47.352Z
Updated: 2024-08-02T15:18:37.188Z
Reserved: 2023-05-09T06:07:41.363Z
Link: CVE-2023-32467
Vulnrichment
Updated: 2024-08-02T15:18:37.188Z
NVD
Status : Modified
Published: 2024-07-10T03:15:01.870
Modified: 2024-11-21T08:03:24.910
Link: CVE-2023-32467
Redhat
No data.