CVE-2022-24410
high-risk
Published 2023-02-10
Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces.
Do I need to act?
-
0.06% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.8/10
Medium
PHYSICAL
/ HIGH complexity
Affected Products (20)
Alienware 13 R2 Firmware
Alienware 13 R3 Firmware
Alienware 15 R2 Firmware
Alienware 15 R3 Firmware
Alienware 15 R4 Firmware
Alienware 17 R3 Firmware
Alienware 17 R4 Firmware
Alienware 17 R5 Firmware
Alienware Aurora R7 Firmware
Alienware Aurora R9 Firmware
Alienware M15 R1 Firmware
Alienware M17 R1 Firmware
Affected Vendors
References (2)
Vendor Advisory
https://www.dell.com/support/kbdoc/en-us/000205719/dsa-2022-325
Vendor Advisory
https://www.dell.com/support/kbdoc/en-us/000205719/dsa-2022-325
51
/ 100
high-risk
Severity
18/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
33/34 · Critical