CVE-2022-24415: Buffer Overflow
Published Mar 11, 2022
·Updated
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
Affected Software
92 affected components
Dell Alienware 13 R3 Firmware<1.16.1
Dell Alienware 13 R3
Dell Alienware 15 R3 Firmware<1.16.1
Dell Alienware 15 R3
Dell Alienware 15 R4 Firmware<1.17.0
Dell Alienware 15 R4
Dell Alienware 17 R4 Firmware<1.16.1
Dell Alienware 17 R4
Dell Alienware 17 R5 Firmware<1.17.0
Dell Alienware 17 R5
Dell Alienware Area 51m R1 Firmware<1.18.0
Dell Alienware Area 51m R1
Dell Alienware Area 51m R2 Firmware<1.13.0
Dell Alienware Area 51m R2
Dell Alienware Aurora R8 Firmware<1.0.20
Dell Alienware Aurora R8
Dell Alienware M15 R2 Firmware<1.12.0
Dell Alienware M15 R2
Dell Alienware M15 R3 Firmware<1.14.0
Dell Alienware M15 R3
Dell Alienware M15 R4 Firmware<1.8.0
Dell Alienware M15 R4
Dell Alienware M17 R2 Firmware<1.12.0
Dell Alienware M17 R2
Dell Alienware M17 R3 Firmware<1.14.0
Dell Alienware M17 R3
Dell Alienware M17 R4 Firmware<1.8.0
Dell Alienware M17 R4
Dell Alienware X15 R1 Firmware<1.7.0
Dell Alienware X15 R1
Dell Alienware X17 R1 Firmware<1.7.0
Dell Alienware X17 R1
Dell Edge Gateway 3000 Firmware<1.7.0
Dell Edge Gateway 3000
Dell Edge Gateway 5000 Firmware<1.17.0
Dell Edge Gateway 5000
Dell Edge Gateway 5100 Firmware<1.17.0
Dell Edge Gateway 5100
Dell Embedded Box Pc 3000 Firmware<1.13.0
Dell Embedded Box Pc 3000
Dell Embedded Box Pc 5000 Firmware<1.14.0
Dell Embedded Box Pc 5000
Dell Inspiron 14 3473 Firmware<1.14.0
Dell Inspiron 14 3473
Dell Inspiron 15 3573 Firmware<1.14.0
Dell Inspiron 15 3573
Dell Inspiron 15 5566 Firmware<1.18.0
Dell Inspiron 15 5566
Dell Inspiron 3277 Firmware<1.19.0
Dell Inspiron 3277
Dell Inspiron 3465 Firmware<1.12.0
Dell Inspiron 3465
Dell Inspiron 3477 Firmware<1.19.0
Dell Inspiron 3477
Dell Inspiron 3482 Firmware<1.13.0
Dell Inspiron 3482
Dell Inspiron 3502 Firmware<1.7.0
Dell Inspiron 3502
Dell Inspiron 3510 Firmware<1.6.0
Dell Inspiron 3510
Dell Inspiron 3565 Firmware<1.12.0
Dell Inspiron 3565
Dell Inspiron 3582 Firmware<1.13.0
Dell Inspiron 3582
Dell Inspiron 3782 Firmware<1.13.0
Dell Inspiron 3782
Dell Latitude 3379 Firmware<1.0.34
Dell Latitude 3379
Dell Vostro 14 5468 Firmware<1.19.0
Dell Vostro 14 5468
Dell Vostro 15 5568 Firmware<1.19.0
Dell Vostro 15 5568
Dell Vostro 3267 Firmware<1.20.0
Dell Vostro 3267
Dell Vostro 3268 Firmware<1.20.0
Dell Vostro 3268
Dell Vostro 3572 Firmware<1.14.0
Dell Vostro 3572
Dell Vostro 3582 Firmware<1.13.0
Dell Vostro 3582
Dell Vostro 3660 Firmware<1.20.0
Dell Vostro 3660
Dell Vostro 3667 Firmware<1.20.0
Dell Vostro 3667
Dell Vostro 3668 Firmware<1.20.0
Dell Vostro 3668
Dell Vostro 3669 Firmware<1.20.0
Dell Vostro 3669
Dell Wyse 7040 Thin Client Firmware<1.15.0
Dell Wyse 7040 Thin Client
Dell Xps 8930 Firmware<1.1.21
Dell Xps 8930
Event History
Mar 11, 2022
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-24415?
CVE-2022-24415 is rated as a medium severity vulnerability.
2
How do I fix CVE-2022-24415?
To fix CVE-2022-24415, update the affected Dell BIOS firmware to the latest available version.
3
Which Dell systems are affected by CVE-2022-24415?
CVE-2022-24415 affects various Dell Alienware systems and some other Dell models with specific firmware versions.
4
Can CVE-2022-24415 lead to significant exploitation risks?
Yes, CVE-2022-24415 could allow a local authenticated user to execute arbitrary code, posing serious security risks.
5
Is there a workaround for CVE-2022-24415 until the firmware is updated?
Currently, there is no known workaround for CVE-2022-24415; updating firmware is the only mitigation.