René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

150 lines
4.2 KiB
JSON

{
"id": "CVE-2022-34390",
"sourceIdentifier": "security_alert@emc.com",
"published": "2022-10-12T20:15:11.117",
"lastModified": "2022-10-13T18:25:59.807",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM."
},
{
"lang": "es",
"value": "Dell BIOS contiene una vulnerabilidad de uso de variables no inicializadas. Un usuario malicioso autenticado localmente puede explotar potencialmente esta vulnerabilidad al usar una SMI para conseguir una ejecuci\u00f3n de c\u00f3digo arbitrario en la SMRAM"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
},
{
"source": "security_alert@emc.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 0.8,
"impactScore": 6.0
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-908"
}
]
},
{
"source": "security_alert@emc.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-457"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:dell:alienware_area-51_r5_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.0.6",
"matchCriteriaId": "1EA2C555-09DA-414E-8D45-EC918C8810BE"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:dell:alienware_area-51_r5:-:*:*:*:*:*:*:*",
"matchCriteriaId": "2C06505A-EA9C-4F4A-8361-D115AE143358"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:dell:alienware_area-51_r4_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.0.6",
"matchCriteriaId": "111F8269-8B83-41C1-8884-7888EDD0BF2E"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:dell:alienware_area-51_r4:-:*:*:*:*:*:*:*",
"matchCriteriaId": "776E24AF-9F3A-48B4-87D2-277616AFD21E"
}
]
}
]
}
],
"references": [
{
"url": "https://www.dell.com/support/kbdoc/000203882",
"source": "security_alert@emc.com",
"tags": [
"Vendor Advisory"
]
}
]
}