DSA-2023-048: Dell Client Platform Security Update for Multiple Insyde UEFI BIOS Vulnerabilities

Summary: Dell Client Platform remediation is available for multiple Insyde UEFI BIOS vulnerabilities that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Third-Party Component CVE(s) More information
Insyde UEFI BIOS CVE-2022-29276 See NVD (http://nvd.nist.gov/)This hyperlink is taking you to a website outside of Dell Technologies. or the following advisories for individual scores for each CVE.
INSYDE-SA-2022025This hyperlink is taking you to a website outside of Dell Technologies.
INSYDE-SA-2022059This hyperlink is taking you to a website outside of Dell Technologies.
INSYDE-SA-2022061This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2021-38489
CVE-2022-29278

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product BIOS Update Version BIOS Release Date
Alienware m15 R7 AMD 1.7.0 3/13/2023
Alienware m15 Ryzen Edition R5 1.12.1 5/8/2023
Alienware m17 R5 AMD 1.7.0 3/13/2023
Dell G15 5515 1.11.1 5/8/2023
Dell G5 SE 5505 1.15.0 4/12/2023
Dell G15 5525 1.7.0 3/13/2023
Inspiron 14 5435 1.3.0 5/8/2023
Inspiron 14 7425 2-in-1 1.11.0 4/6/2023
Inspiron 14 7435 2-in-1 1.3.0 5/8/2023
Inspiron 15 3535 1.2.0 4/13/2023
Inspiron 16 5635 1.3.0 5/8/2023
Inspiron 16 7635 2-in-1 1.3.0 5/8/2023
Inspiron 24 5415 All-in-One 1.10.0 3/13/2023
Inspiron 3505 1.12.0 4/11/2023
Inspiron 3515 1.12.0 4/11/2023
Inspiron 3525 1.9.0 3/10/2023
Inspiron 3585 1.13.0 5/9/2023
Inspiron 3785 1.13.0 5/9/2023
Inspiron 5405 1.11.0 4/11/2023
Inspiron 5415 1.15.0 3/9/2023
Inspiron 5425 1.7.0 3/10/2023
Inspiron 5485 2.14.0 4/11/2023
Inspiron 5485  2-in-1 2.14.0 4/11/2023
Inspiron 5505 1.11.0 4/11/2023
Inspiron 5515 1.15.0 3/9/2023
Inspiron 5585 2.14.0 4/11/2023
Inspiron 7405 2-in-1 1.12.0 4/11/2023
Inspiron 7415 1.15.0 3/10/2023
Vostro 14 3435 1.2.0 4/13/2023
Vostro 15 3535 1.2.0 4/13/2023
Vostro 3405 1.12.0 4/11/2023
Vostro 3425 1.9.0 3/10/2023
Vostro 3515 1.12.0 4/11/2023
Vostro 3525 1.9.0 3/10/2023
Vostro 5415 1.15.0 3/9/2023
Vostro 5515 1.15.0 3/9/2023
Vostro 5625 1.7.0 3/10/2023
Vostro 5635 1.3.0 5/8/2023
Product BIOS Update Version BIOS Release Date
Alienware m15 R7 AMD 1.7.0 3/13/2023
Alienware m15 Ryzen Edition R5 1.12.1 5/8/2023
Alienware m17 R5 AMD 1.7.0 3/13/2023
Dell G15 5515 1.11.1 5/8/2023
Dell G5 SE 5505 1.15.0 4/12/2023
Dell G15 5525 1.7.0 3/13/2023
Inspiron 14 5435 1.3.0 5/8/2023
Inspiron 14 7425 2-in-1 1.11.0 4/6/2023
Inspiron 14 7435 2-in-1 1.3.0 5/8/2023
Inspiron 15 3535 1.2.0 4/13/2023
Inspiron 16 5635 1.3.0 5/8/2023
Inspiron 16 7635 2-in-1 1.3.0 5/8/2023
Inspiron 24 5415 All-in-One 1.10.0 3/13/2023
Inspiron 3505 1.12.0 4/11/2023
Inspiron 3515 1.12.0 4/11/2023
Inspiron 3525 1.9.0 3/10/2023
Inspiron 3585 1.13.0 5/9/2023
Inspiron 3785 1.13.0 5/9/2023
Inspiron 5405 1.11.0 4/11/2023
Inspiron 5415 1.15.0 3/9/2023
Inspiron 5425 1.7.0 3/10/2023
Inspiron 5485 2.14.0 4/11/2023
Inspiron 5485  2-in-1 2.14.0 4/11/2023
Inspiron 5505 1.11.0 4/11/2023
Inspiron 5515 1.15.0 3/9/2023
Inspiron 5585 2.14.0 4/11/2023
Inspiron 7405 2-in-1 1.12.0 4/11/2023
Inspiron 7415 1.15.0 3/10/2023
Vostro 14 3435 1.2.0 4/13/2023
Vostro 15 3535 1.2.0 4/13/2023
Vostro 3405 1.12.0 4/11/2023
Vostro 3425 1.9.0 3/10/2023
Vostro 3515 1.12.0 4/11/2023
Vostro 3525 1.9.0 3/10/2023
Vostro 5415 1.15.0 3/9/2023
Vostro 5515 1.15.0 3/9/2023
Vostro 5625 1.7.0 3/10/2023
Vostro 5635 1.3.0 5/8/2023

Workarounds & Mitigations

None

Revision History

RevisionDateDescription
1.02023-04-11Initial Release
1.12023-05-09Final Platform Release Update and CVE Identifier updated

Related Information

Affected Products

Alienware M15, Alienware m17 R5 AMD, Vostro, Alienware m15, Dell G15 5525, Inspiron 5415, Product Security Information
Article Properties
Article Number: 000212207
Article Type: Dell Security Advisory
Last Modified: 09 May 2023
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.