SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-48674

Dell Platform BIOS contains an Improper Null Termination vulnerability.

MEDIUM 4.9EPSS 0.49%

Does this matter?

Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.

Description

Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.

CVSS 3.1
4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
EPSS
0.49% probability · 41th percentile
CISA KEV
Not listed
Weakness
CWE-170
Affected
dell/precision 3430 tower firmware · dell/precision 3431 tower firmware · dell/precision 3630 tower firmware · dell/precision 5820 tower firmware · dell/precision 7820 tower firmware · dell/precision 7920 tower firmware · dell/latitude 5280 firmware · dell/latitude 5288 firmware · dell/latitude 5290 firmware · dell/latitude 5290 2-in-1 firmware · dell/latitude 5300 firmware · dell/latitude 5300 2-in-1 firmware · dell/latitude 5310 firmware · dell/latitude 5310 2-in-1 firmware · dell/latitude 5320 firmware · dell/latitude 5330 firmware · dell/latitude 5340 firmware · dell/latitude 5400 firmware · dell/latitude 5401 firmware · dell/latitude 5410 firmware · +40 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.