SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-29083

Prior Dell BIOS versions contain an Improper Authentication vulnerability.

MEDIUM 6.8EPSS 0.37%

Does this matter?

Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.

Description

Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.37% probability · 31th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
dell/chengming 3980 firmware · dell/chengming 3990 firmware · dell/chengming 3991 firmware · dell/g3 3579 firmware · dell/g3 3779 firmware · dell/g5 5587 firmware · dell/g5 5000 firmware · dell/g5 5090 firmware · dell/g7 7588 firmware · dell/inspiron 3470 firmware · dell/inspiron 3480 firmware · dell/inspiron 3493 firmware · dell/inspiron 3501 firmware · dell/inspiron 3580 firmware · dell/inspiron 3593 firmware · dell/inspiron 3670 firmware · dell/inspiron 3780 firmware · dell/inspiron 3790 firmware · dell/inspiron 3793 firmware · dell/inspiron 3880 firmware · +40 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.