CVE-2022-26863: Input Validation
Published Jun 23, 2022
·Updated
Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.
Affected Software
68 affected components
Dell Alienware M15 R5 Firmware<1.5.0
Dell Alienware M15 R5
Dell G15 5515 Firmware<1.6.0
Dell G15 5515
Dell G5 Se 5505 Firmware<1.11.0
Dell G5 Se 5505
Dell Inspiron 27 7775 Firmware<2.16.1
Dell Inspiron 27 7775
Dell Inspiron 14 5425 Firmware<1.2.1
Dell Inspiron 14 5425
Dell Inspiron 3275 Firmware<1.9.0
Dell Inspiron 3275
Dell Inspiron 3475 Firmware<1.9.0
Dell Inspiron 3475
Dell Inspiron 3180 Firmware<1.4.4
Dell Inspiron 3180
Dell Inspiron 3185 Firmware<1.4.4
Dell Inspiron 3185
Dell Inspiron 3195 Firmware<1.4.1
Dell Inspiron 3195
Dell Inspiron 3505 Firmware<1.6.0
Dell Inspiron 3505
Dell Inspiron 3515 Firmware<1.5.0
Dell Inspiron 3515
Dell Inspiron 3525 Firmware<1.3.0
Dell Inspiron 3525
Dell Inspiron 3585 Firmware<1.7.0
Dell Inspiron 3585
Dell Inspiron 3595 Firmware<1.3.0
Dell Inspiron 3595
Dell Inspiron 3785 Firmware<1.7.0
Dell Inspiron 3785
Dell Inspiron 5405 Firmware<1.7.0
Dell Inspiron 5405
Dell Inspiron 5415 Firmware<1.9.0
Dell Inspiron 5415
Dell Inspiron 5415 All-in-one Firmware<1.5.0
Dell Inspiron 5415 All-in-one
Dell Inspiron 5485 Firmware<2.8.0
Dell Inspiron 5485
Dell Inspiron 5505 Firmware<1.7.0
Dell Inspiron 5505
Dell Inspiron 5515 Firmware<1.9.0
Dell Inspiron 5515
Dell Inspiron 5575 Firmware<1.6.0
Dell Inspiron 5575
Dell Inspiron 5585 Firmware<2.8.0
Dell Inspiron 5585
Dell Inspiron 7375 Firmware<1.7.0
Dell Inspiron 7375
Dell Inspiron 7405 Firmware<1.8.0
Dell Inspiron 7405
Dell Inspiron 7415 Firmware<1.9.0
Dell Inspiron 7415
Dell Inspiron 7425 Firmware<1.2.1
Dell Inspiron 7425
Dell Vostro 3405 Firmware<1.6.0
Dell Vostro 3405
Dell Vostro 3515 Firmware<1.5.0
Dell Vostro 3515
Dell Vostro 3525 Firmware<1.3.0
Dell Vostro 3525
Dell Vostro 5415 Firmware<1.9.0
Dell Vostro 5415
Dell Vostro 5515 Firmware<1.9.0
Dell Vostro 5515
Dell Vostro 5625 Firmware<1.2.1
Dell Vostro 5625
Event History
Jun 23, 2022
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-26863?
CVE-2022-26863 is categorized as a medium severity vulnerability.
2
Who can exploit CVE-2022-26863?
A locally authenticated malicious user can exploit CVE-2022-26863.
3
What systems are affected by CVE-2022-26863?
CVE-2022-26863 affects various Dell BIOS versions, specifically prior versions up to 1.5.0 or later, depending on the specific hardware.
4
How do I mitigate CVE-2022-26863?
To mitigate CVE-2022-26863, users should update their Dell BIOS to the latest version provided by Dell.
5
What does CVE-2022-26863 vulnerability technically involve?
CVE-2022-26863 involves an input validation vulnerability that allows bypassing security controls in the System Management Mode (SMM).