SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-32475

Dell BIOS contains a missing support for integrity check vulnerability.

HIGH 7.6EPSS 0.17%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system.

CVSS 3.1
7.6 HIGHCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
0.17% probability · 6th percentile
CISA KEV
Not listed
Weakness
CWE-353
Affected
dell/vostro 5625 firmware · dell/vostro 5515 firmware · dell/vostro 5415 firmware · dell/vostro 3405 firmware · dell/vostro 16 5635 firmware · dell/vostro 15 3535 firmware · dell/vostro 15 3525 firmware · dell/vostro 15 3515 firmware · dell/vostro 14 3435 firmware · dell/vostro 14 3425 firmware · dell/inspiron 7415 2-in-1 firmware · dell/inspiron 7405 2-in-1 firmware · dell/inspiron 5515 firmware · dell/inspiron 5505 firmware · dell/inspiron 5415 firmware · dell/inspiron 5405 firmware · dell/inspiron 3505 firmware · dell/inspiron 24 5415 all-in-one firmware · dell/inspiron 16 7635 2-in-1 firmware · dell/inspiron 16 5635 firmware · +20 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.