SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24410

Dell BIOS contains an information exposure vulnerability.

MEDIUM 4.2EPSS 0.17%

Does this matter?

Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.

Description

Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces.

CVSS 3.1
4.2 MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.17% probability · 7th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-312
Affected
dell/alienware 13 r2 firmware · dell/alienware 13 r3 firmware · dell/alienware 15 r2 firmware · dell/alienware 15 r3 firmware · dell/alienware 15 r4 firmware · dell/alienware 17 r3 firmware · dell/alienware 17 r4 firmware · dell/alienware 17 r5 firmware · dell/alienware area 51m r1 firmware · dell/alienware area 51m r2 firmware · dell/alienware aurora r11 firmware · dell/alienware aurora r7 firmware · dell/alienware aurora r8 firmware · dell/alienware aurora r9 firmware · dell/alienware m15 r1 firmware · dell/alienware m15 r2 firmware · dell/alienware m15 r3 firmware · dell/alienware m15 r4 firmware · dell/alienware m15 r6 firmware · dell/alienware m17 r1 firmware · +40 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.