Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

Article Number: 000202711


DSA-2022-221: Dell Networking Security Update for a BIOS Vulnerability

Summary: Dell Networking remediation is available for a BIOS Vulnerability that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2022-34383  Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentially exploit this vulnerability by using an SMI to bypass PMC mitigation and gain arbitrary code execution during SMM. 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2022-34383  Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentially exploit this vulnerability by using an SMI to bypass PMC mitigation and gain arbitrary code execution during SMM. 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

CVE Addressed Product Affected Versions Updated Version Link to Update
CVE-2022-34383 Dell Edge Gateway 5200 Versions before 1.03.10 1.03.10  Dell Edge Gateway 5200 drivers 
CVE Addressed Product Affected Versions Updated Version Link to Update
CVE-2022-34383 Dell Edge Gateway 5200 Versions before 1.03.10 1.03.10  Dell Edge Gateway 5200 drivers 

Acknowledgements

Dell Technologies would like to thank yngweijw for reporting this issue.

Revision History

RevisionDateDescription
1.02022-08-24Initial Release

Related Information


Article Properties


Affected Product

Dell Edge Gateway 5200

Product

Product Security Information

Last Published Date

30 Aug 2022

Article Type

Dell Security Advisory