Description
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
Published: 2024-07-10
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-36716 Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
History

Thu, 26 Sep 2024 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell powerswitch Z9664f On-bios
Weaknesses CWE-125
CPEs cpe:2.3:a:dell:powerswitch_z9664f_on-bios:*:*:*:*:*:*:*:*
Vendors & Products Dell powerswitch Z9664f On-bios
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell edge Gateway 3200
Dell edge Gateway 3200 Firmware
Dell edge Gateway 5200
Dell edge Gateway 5200 Firmware
Weaknesses CWE-787
CPEs cpe:2.3:h:dell:edge_gateway_3200:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:edge_gateway_5200:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:edge_gateway_3200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:edge_gateway_5200_firmware:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell edge Gateway 3200
Dell edge Gateway 3200 Firmware
Dell edge Gateway 5200
Dell edge Gateway 5200 Firmware

Subscriptions

Dell Edge Gateway 3200 Edge Gateway 3200 Firmware Edge Gateway 5200 Edge Gateway 5200 Firmware Powerswitch Z9664f On-bios
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-26T11:57:38.816Z

Reserved: 2023-05-09T06:07:41.364Z

Link: CVE-2023-32472

cve-icon Vulnrichment

Updated: 2024-08-02T15:18:37.025Z

cve-icon NVD

Status : Modified

Published: 2024-07-10T03:15:02.193

Modified: 2024-11-21T08:03:25.637

Link: CVE-2023-32472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses