VulnerabilityModified
CVE-2022-29083
Prior Dell BIOS versions contain an Improper Authentication vulnerability.
MEDIUM 6.8EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.37% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- dell/chengming 3980 firmware · dell/chengming 3990 firmware · dell/chengming 3991 firmware · dell/g3 3579 firmware · dell/g3 3779 firmware · dell/g5 5587 firmware · dell/g5 5000 firmware · dell/g5 5090 firmware · dell/g7 7588 firmware · dell/inspiron 3470 firmware · dell/inspiron 3480 firmware · dell/inspiron 3493 firmware · dell/inspiron 3501 firmware · dell/inspiron 3580 firmware · dell/inspiron 3593 firmware · dell/inspiron 3670 firmware · dell/inspiron 3780 firmware · dell/inspiron 3790 firmware · dell/inspiron 3793 firmware · dell/inspiron 3880 firmware · +40 more
- Source
- security_alert@emc.com
References
- https://www.dell.com/support/kbdoc/000201396Vendor Advisory
- https://www.dell.com/support/kbdoc/000201396Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.