SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-22567

Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability.

MEDIUM 5.1EPSS 0.14%

Does this matter?

Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.

Description

Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware.

CVSS 3.1
5.1 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
EPSS
0.14% probability · 4th percentile
CISA KEV
Not listed
Weakness
CWE-345
Affected
dell/alienware area 51m r1 firmware · dell/alienware area 51m r2 firmware · dell/alienware m15 r3 firmware · dell/alienware m15 r4 firmware · dell/alienware m15 r6 firmware · dell/alienware m17 r3 firmware · dell/alienware m17 r4 firmware · dell/chengming 3990 firmware · dell/chengming 3991 firmware · dell/g15 5510 firmware · dell/g15 5511 firmware · dell/g3 3500 firmware · dell/g3 3590 firmware · dell/g5 5000 firmware · dell/g5 5500 firmware · dell/g7 7500 firmware · dell/g7 7700 firmware · dell/inspiron 14 5410 firmware · dell/inspiron 14 5418 firmware · dell/inspiron 15 5510 firmware · +40 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.