cvelist/2022/22xxx/CVE-2022-22567.json

72 lines
2.3 KiB
JSON
Raw Normal View History

2022-01-04 18:01:10 +00:00
{
"CVE_data_meta": {
2022-02-09 14:55:00 -05:00
"ASSIGNER": "secure@dell.com",
"DATE_PUBLIC": "2022-02-07",
2022-01-04 18:01:10 +00:00
"ID": "CVE-2022-22567",
2022-02-09 14:55:00 -05:00
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "CPG BIOS",
"version": {
"version_data": [
{
"version_affected": "<",
"version_value": "1.15"
}
]
}
}
]
},
"vendor_name": "Dell"
}
]
}
2022-01-04 18:01:10 +00:00
},
2022-02-09 14:55:00 -05:00
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
2022-01-04 18:01:10 +00:00
"description": {
"description_data": [
{
"lang": "eng",
2022-02-09 14:55:00 -05:00
"value": "Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware."
}
]
},
"impact": {
"cvss": {
"baseScore": 4.7,
"baseSeverity": "Medium",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:L",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-345: Insufficient Verification of Data Authenticity"
}
]
}
]
},
"references": {
"reference_data": [
{
2022-02-09 21:01:19 +00:00
"refsource": "MISC",
"url": "https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028",
"name": "https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028"
2022-01-04 18:01:10 +00:00
}
]
}
}