DSA-2023-342: Security Update for a Dell Client BIOS Vulnerability
Summary: Dell Client BIOS remediation is available for an improper input validation vulnerability that could be exploited by malicious users to compromise the affected systems.
Impact
Medium
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-39251 | Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability in order to corrupt memory on the system. | 6.7 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-39251 | Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability in order to corrupt memory on the system. | 6.7 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L |
Affected Products & Remediation
| Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
BIOS Release Date |
Link |
|---|---|---|---|---|---|
| Alienware m15 R6 |
BIOS |
Versions prior to 1.27.0 |
1.27.0 or later |
01/08/2024 |
|
| Dell G15 5511 |
BIOS |
Versions prior to 1.26.0 |
1.26.0 or later |
01/08/2024 |
|
| Inspiron 7510 |
BIOS |
Versions prior to 1.20.0 |
1.20.0 or later |
12/13/2023 |
|
| Inspiron 7610 |
BIOS |
Versions prior to 1.20.0 |
1.20.0 or later |
12/13/2023 |
|
| Latitude 5430 Rugged Laptop |
BIOS |
Versions prior to 1.23.0 |
1.23.0 or later |
12/13/2023 |
|
| Latitude 5521 |
BIOS |
Versions prior to 1.27.0 |
1.27.0 or later |
12/13/2023 |
|
| Latitude 7330 Rugged Laptop |
BIOS |
Versions prior to 1.23.0 |
1.23.0 or later |
12/13/2023 |
|
| Latitude 5421 |
BIOS |
Versions prior to 1.26.0 |
1.26.0 or later |
12/19/2023 |
|
| Precision 3561 |
BIOS |
Versions prior to 1.27.0 |
1.27.0 or later |
12/13/2023 |
|
| Precision 5560 |
BIOS |
Versions prior to 1.25.0 |
1.25.0 or later |
12/15/2023 |
|
| Precision 5760 |
BIOS |
Versions prior to 1.24.0 |
1.24.0 or later |
12/12/2023 |
|
| Precision 7560 |
BIOS |
Versions prior to 1.27.0 |
1.27.0 or later |
12/14/2023 |
|
| Precision 7760 |
BIOS |
Versions prior to 1.27.0 |
1.27.0 or later |
12/14/2023 |
|
| Vostro 7510 |
BIOS |
Versions prior to 1.20.0 |
1.20.0 or later |
12/13/2023 |
|
| XPS 15 9510 |
BIOS |
Versions prior to 1.25.0 |
1.25.0 or later |
12/15/2023 |
|
| XPS 17 9710 |
BIOS |
Versions prior to 1.24.0 |
1.24.0 or later |
12/12/2023 |
| Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
BIOS Release Date |
Link |
|---|---|---|---|---|---|
| Alienware m15 R6 |
BIOS |
Versions prior to 1.27.0 |
1.27.0 or later |
01/08/2024 |
|
| Dell G15 5511 |
BIOS |
Versions prior to 1.26.0 |
1.26.0 or later |
01/08/2024 |
|
| Inspiron 7510 |
BIOS |
Versions prior to 1.20.0 |
1.20.0 or later |
12/13/2023 |
|
| Inspiron 7610 |
BIOS |
Versions prior to 1.20.0 |
1.20.0 or later |
12/13/2023 |
|
| Latitude 5430 Rugged Laptop |
BIOS |
Versions prior to 1.23.0 |
1.23.0 or later |
12/13/2023 |
|
| Latitude 5521 |
BIOS |
Versions prior to 1.27.0 |
1.27.0 or later |
12/13/2023 |
|
| Latitude 7330 Rugged Laptop |
BIOS |
Versions prior to 1.23.0 |
1.23.0 or later |
12/13/2023 |
|
| Latitude 5421 |
BIOS |
Versions prior to 1.26.0 |
1.26.0 or later |
12/19/2023 |
|
| Precision 3561 |
BIOS |
Versions prior to 1.27.0 |
1.27.0 or later |
12/13/2023 |
|
| Precision 5560 |
BIOS |
Versions prior to 1.25.0 |
1.25.0 or later |
12/15/2023 |
|
| Precision 5760 |
BIOS |
Versions prior to 1.24.0 |
1.24.0 or later |
12/12/2023 |
|
| Precision 7560 |
BIOS |
Versions prior to 1.27.0 |
1.27.0 or later |
12/14/2023 |
|
| Precision 7760 |
BIOS |
Versions prior to 1.27.0 |
1.27.0 or later |
12/14/2023 |
|
| Vostro 7510 |
BIOS |
Versions prior to 1.20.0 |
1.20.0 or later |
12/13/2023 |
|
| XPS 15 9510 |
BIOS |
Versions prior to 1.25.0 |
1.25.0 or later |
12/15/2023 |
|
| XPS 17 9710 |
BIOS |
Versions prior to 1.24.0 |
1.24.0 or later |
12/12/2023 |
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-12-19 | Initial Release |
| 2.0 | 2024-01-12 | Final Platform List Update |
Acknowledgements
Dell Technologies would like to thank Eason for reporting this issue.