SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-32480

Dell BIOS contains an Improper Input Validation vulnerability.

MEDIUM 6.8EPSS 0.32%

Does this matter?

Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.

Description

Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.32% probability · 25th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
dell/alienware m15 r7 firmware · dell/g15 5510 firmware · dell/g15 5520 firmware · dell/inspiron 14 5410 firmware · dell/inspiron 14 5418 firmware · dell/inspiron 15 5510 firmware · dell/inspiron 15 5518 firmware · dell/inspiron 16 7620 2-in-1 firmware · dell/inspiron 3520 firmware · dell/inspiron 5410 firmware · dell/inspiron 5420 firmware · dell/inspiron 5620 firmware · dell/inspiron 7420 firmware · dell/inspiron 7510 firmware · dell/inspiron 7610 firmware · dell/latitude 3320 firmware · dell/latitude 3420 firmware · dell/latitude 3430 firmware · dell/latitude 3520 firmware · dell/latitude 3530 firmware · +11 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.