High
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
CVE-2022-24417 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 7.5 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
CVE-2022-24418 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 7.5 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
CVE-2022-24417 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 7.5 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
CVE-2022-24418 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM. | 7.5 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Product | Minimum BIOS Version | BIOS Release Date (MM/DD/YYYY) |
Dell G5 5505 | 1.10.0 | 02/21/2022 |
Inspiron 22-3275 | 1.8.0 | 02/23/2022 |
Inspiron 24-3475 | 1.8.0 | 02/23/2022 |
Inspiron 27 7775 | 2.15.0 | 02/24/2022 |
Inspiron 3180 | 1.4.4 | 04/13/2022 |
Inspiron 3185 | 1.4.4 | 04/13/2022 |
Inspiron 3195 2-in-1 | 1.4.1 | 04/13/2022 |
Inspiron 3505 | 1.5.0 | 02/18/2022 |
Inspiron 3515 | 1.4.0 | 02/18/2022 |
Inspiron 3585 | 1.6.0 | 02/18/2022 |
Inspiron 3595 | 1.2.1 | 02/28/2022 |
Inspiron 3785 | 1.6.0 | 02/18/2022 |
Inspiron 5405 | 1.6.0 | 02/22/2022 |
Inspiron 5415 | 1.7.1 | 02/16/2022 |
Inspiron 5485 | 2.7.0 | 04/25/2022 |
Inspiron 5485 2-in-1 | 2.7.0 | 04/25/2022 |
Inspiron 5505 | 1.6.0 | 02/22/2022 |
Inspiron 5515 | 1.7.1 | 02/16/2022 |
Inspiron 5575 | 1.5.0 | 02/18/2022 |
Inspiron 5585 | 2.7.0 | 04/25/2022 |
Inspiron 5675 | 1.5.0 | 02/25/2022 |
Inspiron 5775 | 1.5.0 | 02/18/2022 |
Inspiron 7375 | 1.6.0 | 04/26/2022 |
Inspiron 7405 2-in-1 | 1.7.0 | 02/23/2022 |
Inspiron 7415 | 1.7.1 | 02/15/2022 |
Vostro 3405 | 1.5.0 | 02/18/2022 |
Vostro 3515 | 1.4.0 | 02/18/2022 |
Vostro 5415 | 1.7.1 | 02/16/2022 |
Vostro 5515 | 1.7.1 | 02/16/2022 |
Product | Minimum BIOS Version | BIOS Release Date (MM/DD/YYYY) |
Dell G5 5505 | 1.10.0 | 02/21/2022 |
Inspiron 22-3275 | 1.8.0 | 02/23/2022 |
Inspiron 24-3475 | 1.8.0 | 02/23/2022 |
Inspiron 27 7775 | 2.15.0 | 02/24/2022 |
Inspiron 3180 | 1.4.4 | 04/13/2022 |
Inspiron 3185 | 1.4.4 | 04/13/2022 |
Inspiron 3195 2-in-1 | 1.4.1 | 04/13/2022 |
Inspiron 3505 | 1.5.0 | 02/18/2022 |
Inspiron 3515 | 1.4.0 | 02/18/2022 |
Inspiron 3585 | 1.6.0 | 02/18/2022 |
Inspiron 3595 | 1.2.1 | 02/28/2022 |
Inspiron 3785 | 1.6.0 | 02/18/2022 |
Inspiron 5405 | 1.6.0 | 02/22/2022 |
Inspiron 5415 | 1.7.1 | 02/16/2022 |
Inspiron 5485 | 2.7.0 | 04/25/2022 |
Inspiron 5485 2-in-1 | 2.7.0 | 04/25/2022 |
Inspiron 5505 | 1.6.0 | 02/22/2022 |
Inspiron 5515 | 1.7.1 | 02/16/2022 |
Inspiron 5575 | 1.5.0 | 02/18/2022 |
Inspiron 5585 | 2.7.0 | 04/25/2022 |
Inspiron 5675 | 1.5.0 | 02/25/2022 |
Inspiron 5775 | 1.5.0 | 02/18/2022 |
Inspiron 7375 | 1.6.0 | 04/26/2022 |
Inspiron 7405 2-in-1 | 1.7.0 | 02/23/2022 |
Inspiron 7415 | 1.7.1 | 02/15/2022 |
Vostro 3405 | 1.5.0 | 02/18/2022 |
Vostro 3515 | 1.4.0 | 02/18/2022 |
Vostro 5415 | 1.7.1 | 02/16/2022 |
Vostro 5515 | 1.7.1 | 02/16/2022 |
Revision | Date | Description |
1.0 | 2022/05/12 | Initial Release |
Dell would like to thank JiaWei Yin (yngweijw) for reporting CVE-2022-24417 and CVE-2022-24418.