SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-22566

Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability.

HIGH 7.2EPSS 0.26%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
0.26% probability · 17th percentile
CISA KEV
Not listed
Weakness
CWE-1190
Affected
dell/alienware area 51m r1 firmware · dell/alienware area 51m r2 firmware · dell/alienware m15 r3 firmware · dell/alienware m15 r4 firmware · dell/alienware m15 r6 firmware · dell/alienware m17 r3 firmware · dell/alienware m17 r4 firmware · dell/chengming 3990 firmware · dell/chengming 3991 firmware · dell/g15 5510 firmware · dell/g15 5511 firmware · dell/g3 3500 firmware · dell/g3 3590 firmware · dell/g5 5000 firmware · dell/g5 5500 firmware · dell/g7 7500 firmware · dell/g7 7700 firmware · dell/inspiron 14 5410 firmware · dell/inspiron 14 5418 firmware · dell/inspiron 15 5510 firmware · +40 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.