Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.
Metrics
No CVSS v4.0
Attack Vector Physical
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
The EPSS score is 0.00059.
Exploitation none
Automatable no
Technical Impact total
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Dell
Subscribe
|
Alienware M15 R7
Subscribe
Alienware M15 R7 Firmware
Subscribe
Cpg Bios
Subscribe
G15 5510
Subscribe
G15 5510 Firmware
Subscribe
G15 5520
Subscribe
G15 5520 Firmware
Subscribe
Inspiron 14 5410
Subscribe
Inspiron 14 5410 Firmware
Subscribe
Inspiron 14 5418
Subscribe
Inspiron 14 5418 Firmware
Subscribe
Inspiron 15 5510
Subscribe
Inspiron 15 5510 Firmware
Subscribe
Inspiron 15 5518
Subscribe
Inspiron 15 5518 Firmware
Subscribe
Inspiron 16 7620 2-in-1
Subscribe
Inspiron 16 7620 2-in-1 Firmware
Subscribe
Inspiron 3520
Subscribe
Inspiron 3520 Firmware
Subscribe
Inspiron 5410
Subscribe
Inspiron 5410 Firmware
Subscribe
Inspiron 5420
Subscribe
Inspiron 5420 Firmware
Subscribe
Inspiron 5620
Subscribe
Inspiron 5620 Firmware
Subscribe
Inspiron 7420
Subscribe
Inspiron 7420 Firmware
Subscribe
Inspiron 7510
Subscribe
Inspiron 7510 Firmware
Subscribe
Inspiron 7610
Subscribe
Inspiron 7610 Firmware
Subscribe
Latitude 3320
Subscribe
Latitude 3320 Firmware
Subscribe
Latitude 3420
Subscribe
Latitude 3420 Firmware
Subscribe
Latitude 3430
Subscribe
Latitude 3430 Firmware
Subscribe
Latitude 3520
Subscribe
Latitude 3520 Firmware
Subscribe
Latitude 3530
Subscribe
Latitude 3530 Firmware
Subscribe
Precision 5760
Subscribe
Precision 5760 Firmware
Subscribe
Precision 5770
Subscribe
Precision 5770 Firmware
Subscribe
Vostro 3420
Subscribe
Vostro 3420 Firmware
Subscribe
Vostro 3520
Subscribe
Vostro 3520 Firmware
Subscribe
Vostro 5410
Subscribe
Vostro 5410 Firmware
Subscribe
Vostro 5510
Subscribe
Vostro 5510 Firmware
Subscribe
Vostro 5620
Subscribe
Vostro 5620 Firmware
Subscribe
Vostro 7510
Subscribe
Vostro 7510 Firmware
Subscribe
Xps 13 9315 2-in-1
Subscribe
Xps 13 9315 2-in-1 Firmware
Subscribe
Xps 17 9710
Subscribe
Xps 17 9710 Firmware
Subscribe
Xps 17 9720
Subscribe
Xps 17 9720 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
Configuration 26 [-]
| AND |
|
Configuration 27 [-]
| AND |
|
Configuration 28 [-]
| AND |
|
Configuration 29 [-]
| AND |
|
Configuration 30 [-]
| AND |
|
Configuration 31 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-36724 | Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 29 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell cpg Bios
|
|
| CPEs | cpe:2.3:o:dell:cpg_bios:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dell cpg Bios
|
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-11-29T14:39:31.425Z
Reserved: 2023-05-09T06:09:57.042Z
Link: CVE-2023-32480
Updated: 2024-08-02T15:18:37.175Z
Status : Modified
Published: 2023-06-23T11:15:09.937
Modified: 2024-11-21T08:03:26.573
Link: CVE-2023-32480
No data.
OpenCVE Enrichment
No data.
EUVD