Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Physical
0

CVE-2023-32480

Disclosure Date: June 23, 2023
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
6.8 Medium
Impact Score:
5.9
Exploitability Score:
0.9
Vector:
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector (AV):
Physical
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • dell

Products

  • alienware m15 r7 firmware,
  • g15 5510 firmware,
  • g15 5520 firmware,
  • inspiron 14 5410 firmware,
  • inspiron 14 5418 firmware,
  • inspiron 15 5510 firmware,
  • inspiron 15 5518 firmware,
  • inspiron 16 7620 2-in-1 firmware,
  • inspiron 3520 firmware,
  • inspiron 5410 firmware,
  • inspiron 5420 firmware,
  • inspiron 5620 firmware,
  • inspiron 7420 firmware,
  • inspiron 7510 firmware,
  • inspiron 7610 firmware,
  • latitude 3320 firmware,
  • latitude 3420 firmware,
  • latitude 3430 firmware,
  • latitude 3520 firmware,
  • latitude 3530 firmware,
  • precision 5760 firmware,
  • precision 5770 firmware,
  • vostro 3420 firmware,
  • vostro 3520 firmware,
  • vostro 5410 firmware,
  • vostro 5510 firmware,
  • vostro 5620 firmware,
  • vostro 7510 firmware,
  • xps 13 9315 2-in-1 firmware,
  • xps 17 9710 firmware,
  • xps 17 9720 firmware

Additional Info

Technical Analysis