DSA-2023-244: Dell Technologies Networking Edge Gateway Security Update for Multiple SMM Vulnerabilities
Riepilogo: Dell Technologies Networking Edge Gateway remediations are available for Multiple SMM Vulnerabilities that could be exploited by malicious users to compromise the affected system.
Questo articolo si applica a
Questo articolo non si applica a
Questo articolo non è legato a un prodotto specifico.
Non tutte le versioni del prodotto sono identificate in questo articolo.
Impatto
High
Dettagli
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-24415 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 8.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2022-24416 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 8.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2022-24419 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 8.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2022-24420 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 8.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2022-24421 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 8.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-24415 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 8.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2022-24416 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 8.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2022-24419 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 8.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2022-24420 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 8.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVE-2022-24421 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 8.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Prodotti interessati e correzione
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link to Update |
|---|---|---|---|---|
| Dell Edge Gateway 3200 | BIOS Capsule Windows | Versions prior to 1.03.10 | Version 1.03.10 | EGW-3200 BIOS capsule_Windows |
| Dell Edge Gateway 5200 | BIOS Capsule Windows | Versions prior to 1.04.10 | Version 1.04.10 | EGW-5200 BIOS capsule_Windows |
| Dell Edge Gateway 5200 | BIOS Capsule Linux | Versions prior to 1.04.10 | Version 1.04.10 | EGW-5200 BIOS capsule_Linux |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link to Update |
|---|---|---|---|---|
| Dell Edge Gateway 3200 | BIOS Capsule Windows | Versions prior to 1.03.10 | Version 1.03.10 | EGW-3200 BIOS capsule_Windows |
| Dell Edge Gateway 5200 | BIOS Capsule Windows | Versions prior to 1.04.10 | Version 1.04.10 | EGW-5200 BIOS capsule_Windows |
| Dell Edge Gateway 5200 | BIOS Capsule Linux | Versions prior to 1.04.10 | Version 1.04.10 | EGW-5200 BIOS capsule_Linux |
Soluzioni alternative e mitigazioni
None.
Cronologia delle revisioni
| Revision | Date | Description |
| 1.0 | 2023-07-06 | Initial Release |
Informazioni correlate
Dichiarazione di non responsabilità
Prodotti interessati
Dell Edge Gateway 3200, Dell Edge Gateway 5200Proprietà dell'articolo
Numero articolo: 000215608
Tipo di articolo: Dell Security Advisory
Ultima modifica: 06 lug 2023
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.