CVE-2013-3582
Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.
- CVSS 2.0
- 7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 2.59% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- dell/latitude d530 · dell/latitude d531 · dell/latitude d630 · dell/latitude d631 · dell/latitude d830 · dell/latitude e4200 · dell/latitude e4300 · dell/latitude e5400 · dell/latitude e5500 · dell/latitude e6400 · dell/latitude e6400 atg · dell/latitude e6400 atg xfr · dell/latitude e6500 · dell/latitude xt2 · dell/latitude z600 · dell/precision m2300 · dell/precision m2400 · dell/precision m4300 · dell/precision m4400 · dell/precision m6300 · +2 more
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/912156US Government Resource
- http://www.kb.cert.org/vuls/id/BLUU-99HSLAUS Government Resource
- https://media.blackhat.com/us-13/US-13-Butterworth-BIOS-Security-Slides.pdfExploit
- https://media.blackhat.com/us-13/US-13-Butterworth-BIOS-Security-WP.pdfExploit
- https://www.blackhat.com/us-13/archives.html#Butterworth
- http://www.kb.cert.org/vuls/id/912156US Government Resource
- http://www.kb.cert.org/vuls/id/BLUU-99HSLAUS Government Resource
- https://media.blackhat.com/us-13/US-13-Butterworth-BIOS-Security-Slides.pdfExploit
- https://media.blackhat.com/us-13/US-13-Butterworth-BIOS-Security-WP.pdfExploit
- https://www.blackhat.com/us-13/archives.html#Butterworth
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.