MEDIUM · 6.8

CVE-2022-29083

Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing driv...

Vulnerability Description

Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DellChengming 3980 Firmware< 2.23.0
DellChengming 3980-
DellChengming 3990 Firmware< 1.11.0
DellChengming 3990-
DellChengming 3991 Firmware< 1.11.0
DellChengming 3991-
DellG3 3579 Firmware< 1.21.0
DellG3 3579-
DellG3 3779 Firmware< 1.21.0
DellG3 3779-
DellG5 5587 Firmware< 1.21.0
DellG5 5587-
DellG5 5000 Firmware< 1.7.0
DellG5 5000-
DellG5 5090 Firmware< 1.14.0
DellG5 5090-
DellG7 7588 Firmware< 1.21.0
DellG7 7588-
DellInspiron 3470 Firmware< 2.23.0
DellInspiron 3470-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-29083?

CVE-2022-29083 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing driv...

How severe is CVE-2022-29083?

CVE-2022-29083 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-29083?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Chengming 3980 Firmware, Dell Chengming 3980, Dell Chengming 3990 Firmware, Dell Chengming 3990, Dell Chengming 3991 Firmware.