CVE-2022-34407: Buffer Overflow
Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34407?
CVE-2022-34407 has a high severity due to the potential for arbitrary code execution or denial of service by a local attacker with high privileges.
How do I fix CVE-2022-34407?
To fix CVE-2022-34407, update the affected Dell PowerEdge and Precision BIOS to the latest version available.
Which Dell products are affected by CVE-2022-34407?
Affected products include various models of Dell PowerEdge and Dell Precision systems with specific firmware versions prior to 2.9.3.
What can an attacker do if they exploit CVE-2022-34407?
An attacker exploiting CVE-2022-34407 may execute arbitrary code with high privileges or cause a denial of service.
Is there any mitigation for CVE-2022-34407 before applying the fix?
The primary mitigation for CVE-2022-34407 is to restrict physical access to the affected systems.