Article Number: 000204679
High
Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
CVE-2022-34401 | Dell BIOS contains a stack-based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM. | 7.5 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
CVE-2022-34401 | Dell BIOS contains a stack-based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM. | 7.5 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Product | BIOS Update Version | BIOS Release Date (MM/DD/YYYY) |
Alienware m15 A6 | 1.4.3 | 09/29/2022 |
Alienware m17 Ryzen Edition R5 | 1.4.3 | 09/29/2022 |
Dell G15 5525 | 1.4.3 | 09/29/2022 |
Product | BIOS Update Version | BIOS Release Date (MM/DD/YYYY) |
Alienware m15 A6 | 1.4.3 | 09/29/2022 |
Alienware m17 Ryzen Edition R5 | 1.4.3 | 09/29/2022 |
Dell G15 5525 | 1.4.3 | 09/29/2022 |
Dell Technologies would like to thank Cederic Laumen (@ling_sec) for reporting CVE-2022-34401.
Revision | Date | Description |
1.0 | 2022/10/27 | Initial Release |
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide
Alienware M15, Alienware m17 R5 AMD, Alienware m15, Dell G15 5525
01 Nov 2022
1
Dell Security Advisory