DSA-2022-205: Dell Client Precision Workstation 7910 and 7920 Rack BIOS Security Update for Multiple Vulnerabilities

Summary: Dell Precision Workstation Rack remediation is available for multiple vulnerabilities that may be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Proprietary Code CVE  Description CVSS Base Score CVSS Vector String
CVE-2022-22558 Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker may potentially exploit this vulnerability leading to arbitrary writes or denial of service. 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
 
Third-party Component CVEs More information
EDK II CVE-2019-14553 See NVD (http://nvd.nist.gov/) for individual scores for each CVE. This hyperlink is taking you to a website outside of Dell Technologies.
Tianocore EDK2 CVE-2019-14584
CVE-2021-28210
CVE-2021-28211
Proprietary Code CVE  Description CVSS Base Score CVSS Vector String
CVE-2022-22558 Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker may potentially exploit this vulnerability leading to arbitrary writes or denial of service. 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.
 
Third-party Component CVEs More information
EDK II CVE-2019-14553 See NVD (http://nvd.nist.gov/) for individual scores for each CVE. This hyperlink is taking you to a website outside of Dell Technologies.
Tianocore EDK2 CVE-2019-14584
CVE-2021-28210
CVE-2021-28211
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Version Updated Version Link to Update  
 
Precision 7920 Rack Versions before 2.14.2 2.14.2 Precision 7920 Rack  
Precision 7910 Rack Versions before 2.15.0 2.15.0 Precision 7910 Rack  
Product Affected Version Updated Version Link to Update  
 
Precision 7920 Rack Versions before 2.14.2 2.14.2 Precision 7920 Rack  
Precision 7910 Rack Versions before 2.15.0 2.15.0 Precision 7910 Rack  

Revision History

RevisionDateDescription
1.02022-08-04Initial Release

Related Information

Affected Products

Precision 7920 Rack, Precision Rack 7910, Product Security Information
Article Properties
Article Number: 000202141
Article Type: Dell Security Advisory
Last Modified: 08 Jun 2023
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.