MEDIUM · 6.8

CVE-2023-32480

Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.

Vulnerability Description

Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DellAlienware M15 R7 Firmware< 1.17.0
DellAlienware M15 R7-
DellG15 5510 Firmware< 1.19.0
DellG15 5510-
DellG15 5520 Firmware< 1.17.0
DellG15 5520-
DellInspiron 14 5410 Firmware< 2.19.1
DellInspiron 14 5410-
DellInspiron 14 5418 Firmware< 2.19.1
DellInspiron 14 5418-
DellInspiron 15 5510 Firmware< 2.19.1
DellInspiron 15 5510-
DellInspiron 15 5518 Firmware< 2.19.1
DellInspiron 15 5518-
DellInspiron 16 7620 2-In-1 Firmware< 1.12.1
DellInspiron 16 7620 2-In-1-
DellInspiron 3520 Firmware< 1.15.0
DellInspiron 3520-
DellInspiron 5410 Firmware< 2.19.1
DellInspiron 5410-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-32480?

CVE-2023-32480 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Dell BIOS contains an Improper Input Validation vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability to perform arbitrary code execution.

How severe is CVE-2023-32480?

CVE-2023-32480 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-32480?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Alienware M15 R7 Firmware, Dell Alienware M15 R7, Dell G15 5510 Firmware, Dell G15 5510, Dell G15 5520 Firmware.