Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
10 Sep 2024, 20:00
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
References | () https://www.dell.com/support/kbdoc/en-in/000214917/dsa-2023-225-security-update-for-dell-bios-edge-gateway-5200-and-edge-gateway-3200 - Vendor Advisory | |
First Time |
Dell chengming 3977
Dell edge Gateway 3200 Firmware Dell edge Gateway 5000 Firmware Dell xps 13 9350 Dell edge Gateway 3200 Dell edge Gateway 5100 Dell edge Gateway 5200 Firmware Dell xps 13 9350 Firmware Dell chengming 3977 Firmware Dell edge Gateway 5100 Firmware Dell edge Gateway 5000 Dell edge Gateway 5200 Dell |
|
CPE | cpe:2.3:o:dell:edge_gateway_3200_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:dell:chengming_3977_firmware:0.1.13.0:*:*:*:*:*:*:* cpe:2.3:h:dell:chengming_3977:-:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_5200:-:*:*:*:*:*:*:* cpe:2.3:h:dell:xps_13_9350:-:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_5100_firmware:0.1.19.0:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_3200:-:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_5200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dell:xps_13_9350_firmware:0.1.13.0:*:*:*:*:*:*:* cpe:2.3:o:dell:edge_gateway_5000_firmware:0.1.19.0:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_5100:-:*:*:*:*:*:*:* cpe:2.3:h:dell:edge_gateway_5000:-:*:*:*:*:*:*:* |
11 Jul 2024, 13:05
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Jul 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-10 03:15
Updated : 2024-09-10 20:00
NVD link : CVE-2023-32467
Mitre link : CVE-2023-32467
CVE.ORG link : CVE-2023-32467
JSON object : View
Products Affected
dell
- edge_gateway_5100_firmware
- chengming_3977
- xps_13_9350
- edge_gateway_5200
- edge_gateway_5200_firmware
- edge_gateway_5000_firmware
- chengming_3977_firmware
- xps_13_9350_firmware
- edge_gateway_5000
- edge_gateway_3200_firmware
- edge_gateway_3200
- edge_gateway_5100
CWE
CWE-665
Improper Initialization