CVE-2022-34383: OS Command Injection
Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentially exploit this vulnerability by using an SMI to bypass PMC mitigation and gain arbitrary code execution during SMM.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34383?
CVE-2022-34383 has been rated as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2022-34383?
To mitigate CVE-2022-34383, upgrade the Dell Edge Gateway 5200 firmware to version 1.03.10 or later.
Who is affected by CVE-2022-34383?
CVE-2022-34383 affects users of Dell Edge Gateway 5200 running firmware versions prior to 1.03.10.
What is an operating system command injection vulnerability in CVE-2022-34383?
In CVE-2022-34383, a local malicious user can exploit the vulnerability to execute arbitrary commands on the affected system.
Can CVE-2022-34383 be exploited remotely?
CVE-2022-34383 typically requires local access to the affected system, making remote exploitation less likely.