Attacker Value
Unknown
0
CVE-2022-24415
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2022-24415
(Last updated October 07, 2023) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
7.8 High
Impact Score:
5.9
Exploitability Score:
1.8
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
CPG BIOS 1.16
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- alienware 13 r3 firmware,
- alienware 15 r3 firmware,
- alienware 15 r4 firmware,
- alienware 17 r4 firmware,
- alienware 17 r5 firmware,
- alienware area 51m r1 firmware,
- alienware area 51m r2 firmware,
- alienware aurora r8 firmware,
- alienware m15 r2 firmware,
- alienware m15 r3 firmware,
- alienware m15 r4 firmware,
- alienware m17 r2 firmware,
- alienware m17 r3 firmware,
- alienware m17 r4 firmware,
- alienware x15 r1 firmware,
- alienware x17 r1 firmware,
- edge gateway 3000 firmware,
- edge gateway 5000 firmware,
- edge gateway 5100 firmware,
- embedded box pc 3000 firmware,
- embedded box pc 5000 firmware,
- inspiron 14 3473 firmware,
- inspiron 15 3573 firmware,
- inspiron 15 5566 firmware,
- inspiron 3277 firmware,
- inspiron 3465 firmware,
- inspiron 3477 firmware,
- inspiron 3482 firmware,
- inspiron 3502 firmware,
- inspiron 3510 firmware,
- inspiron 3565 firmware,
- inspiron 3582 firmware,
- inspiron 3782 firmware,
- latitude 3379 firmware,
- vostro 14 5468 firmware,
- vostro 15 5568 firmware,
- vostro 3267 firmware,
- vostro 3268 firmware,
- vostro 3572 firmware,
- vostro 3582 firmware,
- vostro 3660 firmware,
- vostro 3667 firmware,
- vostro 3668 firmware,
- vostro 3669 firmware,
- wyse 7040 thin client firmware,
- xps 8930 firmware
References
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: