MEDIUM · 5.7

CVE-2022-22558

Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker could potent...

Vulnerability Description

Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker could potentially exploit this vulnerability leading to arbitrary writes or denial of service.

CVSS Score

5.7

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DellR6415 Firmware< 1.18.0
DellR6415-
DellR7415 Firmware< 1.18.0
DellR7415-
DellR7425 Firmware< 1.18.0
DellR7425-
DellR730 Firmware< 2.14.0
DellR730-
DellR730Xd Firmware< 2.14.0
DellR730Xd-
DellR630 Firmware< 2.14.0
DellR630-
DellC4130 Firmware< 2.14.0
DellC4130-
DellM630 Firmware< 2.14.0
DellM630-
DellM630P Firmware< 2.14.0
DellM630P-
DellFc630 Firmware< 2.14.0
DellFc630-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-22558?

CVE-2022-22558 is a vulnerability with a CVSS score of 5.7 (MEDIUM). Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A Local High Privileged attacker could potent...

How severe is CVE-2022-22558?

CVE-2022-22558 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-22558?

Check the references section above for vendor advisories and patch information. Affected products include: Dell R6415 Firmware, Dell R6415, Dell R7415 Firmware, Dell R7415, Dell R7425 Firmware.