CVE-2022-31223: Low severity dell chengming 3900 vulnerability
Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read memory on the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Dell BIOS vulnerability?
The vulnerability ID for this Dell BIOS vulnerability is CVE-2022-31223.
How does the vulnerability in Dell BIOS versions affect the system?
The vulnerability in Dell BIOS versions allows a local authenticated administrator user to potentially read memory on the system by exploiting an Improper Neutralization of Null Byte vulnerability.
What is the severity of CVE-2022-31223?
The severity of CVE-2022-31223 is low, with a severity value of 2.3.
Which Dell BIOS versions are affected by CVE-2022-31223?
Dell Chengming 3900 Firmware (up to version 1.1.66) and Dell Inspiron 3910 Firmware (up to version 1.1.66) are affected by CVE-2022-31223.
How can the CVE-2022-31223 vulnerability be fixed?
To fix the CVE-2022-31223 vulnerability, Dell recommends updating the BIOS firmware to the latest version available.