MEDIUM · 5.6

CVE-2022-32482

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable...

Vulnerability Description

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVSS Score

5.6

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
LOW

Affected Products

VendorProductVersions
DellAlienware M15 R6 Firmware< 1.17.0
DellAlienware M15 R6-
DellAlienware M15 R7 Firmware< 1.10.0
DellAlienware M15 R7-
DellChengming 3900 Firmware< 1.7.3
DellChengming 3900-
DellG15 5510 Firmware< 1.16.0
DellG15 5510-
DellG15 5511 Firmware< 1.18.0
DellG15 5511-
DellG15 5520 Firmware< 1.10.0
DellG15 5520-
DellG16 7620 Firmware< 1.12.0
DellG16 7620-
DellG3 3500 Firmware< 1.20.0
DellG3 3500-
DellG5 15 5500 Firmware< 1.20.0
DellG5 15 5500-
DellG7 15 7500 Firmware< 1.19.0
DellG7 15 7500-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-32482?

CVE-2022-32482 is a vulnerability with a CVSS score of 5.6 (MEDIUM). Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable...

How severe is CVE-2022-32482?

CVE-2022-32482 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-32482?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Alienware M15 R6 Firmware, Dell Alienware M15 R6, Dell Alienware M15 R7 Firmware, Dell Alienware M15 R7, Dell Chengming 3900 Firmware.