VulnerabilityModified
CVE-2023-32480
Dell BIOS contains an Improper Input Validation vulnerability.
MEDIUM 6.8EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- dell/alienware m15 r7 firmware · dell/g15 5510 firmware · dell/g15 5520 firmware · dell/inspiron 14 5410 firmware · dell/inspiron 14 5418 firmware · dell/inspiron 15 5510 firmware · dell/inspiron 15 5518 firmware · dell/inspiron 16 7620 2-in-1 firmware · dell/inspiron 3520 firmware · dell/inspiron 5410 firmware · dell/inspiron 5420 firmware · dell/inspiron 5620 firmware · dell/inspiron 7420 firmware · dell/inspiron 7510 firmware · dell/inspiron 7610 firmware · dell/latitude 3320 firmware · dell/latitude 3420 firmware · dell/latitude 3430 firmware · dell/latitude 3520 firmware · dell/latitude 3530 firmware · +11 more
- Source
- security_alert@emc.com
References
- https://www.dell.com/support/kbdoc/en-us/000214779/dsa-2023-175-dell-client-bios-security-update-for-an-improper-input-validation-vulnerabilityVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000214779/dsa-2023-175-dell-client-bios-security-update-for-an-improper-input-validation-vulnerabilityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.