CVE-2022-32490: Input Validation
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-32490.
What is the severity of CVE-2022-32490?
The severity of CVE-2022-32490 is high.
How does CVE-2022-32490 affect Dell Edge Gateway 3000 Firmware?
Dell Edge Gateway 3000 Firmware up to version 1.9.0 is affected by CVE-2022-32490.
How does CVE-2022-32490 affect Dell Edge Gateway 5000 Firmware?
Dell Edge Gateway 5000 Firmware up to version 1.19.0 is affected by CVE-2022-32490.
How does CVE-2022-32490 affect Dell Embedded Box Pc 3000 Firmware?
Dell Embedded Box Pc 3000 Firmware up to version 1.15.0 is affected by CVE-2022-32490.
Is Dell Edge Gateway 3000 vulnerable to CVE-2022-32490?
No, Dell Edge Gateway 3000 is not vulnerable to CVE-2022-32490.
Is Dell Edge Gateway 5000 vulnerable to CVE-2022-32490?
No, Dell Edge Gateway 5000 is not vulnerable to CVE-2022-32490.
Is Dell Embedded Box Pc 3000 vulnerable to CVE-2022-32490?
No, Dell Embedded Box Pc 3000 is not vulnerable to CVE-2022-32490.
How can a local authenticated malicious user exploit CVE-2022-32490?
A local authenticated malicious user can exploit CVE-2022-32490 by using an SMI to gain arbitrary code execution in SMRAM.
Where can I find more information about CVE-2022-32490?
You can find more information about CVE-2022-32490 at the following link: [https://www.dell.com/support/kbdoc/000204685](https://www.dell.com/support/kbdoc/000204685)