Medium
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
---|---|---|---|
CVE-2023-32467 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege. | 5.7 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
CVE-2023-32466 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege. | 5.7 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
CVE-2023-32472 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some code in System Management Mode, leading to arbitrary code execution or escalation of privilege. | 5.7 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
CVE-2023-32471 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits. | 6.0 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
---|---|---|---|
CVE-2023-32467 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege. | 5.7 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
CVE-2023-32466 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege. | 5.7 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
CVE-2023-32472 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some code in System Management Mode, leading to arbitrary code execution or escalation of privilege. | 5.7 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
CVE-2023-32471 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits. | 6.0 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
CVEs Addressed | Product | Software/Firmware |
Affected Versions | Remediated Versions | Link |
---|---|---|---|---|---|
CVE-2023-32467 | Dell Edge Gateway 5200 | DXE driver | Versions prior to v1.05.10 | Version v1.05.10 or later | https://www.dell.com/support/home/product-support/product/dell-edge-gateway-5200/drivers |
CVE-2023-32466 | Dell Edge Gateway 3200 | DXE driver | Versions prior to v1.03.10 | Version v1.03.10 or later | https://www.dell.com/support/home/product-support/product/dell-edge-gateway-3200/drivers |
CVE-2023-32472 | Dell Edge Gateway 5200 | SMM | Versions prior to v1.05.10 | Version v1.05.10 or later | https://www.dell.com/support/home/product-support/product/dell-edge-gateway-5200/drivers |
CVE-2023-32471 | Dell Edge Gateway 5200 | DXE driver | Versions prior to v1.05.10 | Version v1.05.10 or later | https://www.dell.com/support/home/product-support/product/dell-edge-gateway-5200/drivers |
CVE-2023-32471 | Dell Edge Gateway 3200 | DXE driver | Versions prior to v1.03.10 | Version v1.03.10 or later | https://www.dell.com/support/home/product-support/product/dell-edge-gateway-3200/drivers |
CVEs Addressed | Product | Software/Firmware |
Affected Versions | Remediated Versions | Link |
---|---|---|---|---|---|
CVE-2023-32467 | Dell Edge Gateway 5200 | DXE driver | Versions prior to v1.05.10 | Version v1.05.10 or later | https://www.dell.com/support/home/product-support/product/dell-edge-gateway-5200/drivers |
CVE-2023-32466 | Dell Edge Gateway 3200 | DXE driver | Versions prior to v1.03.10 | Version v1.03.10 or later | https://www.dell.com/support/home/product-support/product/dell-edge-gateway-3200/drivers |
CVE-2023-32472 | Dell Edge Gateway 5200 | SMM | Versions prior to v1.05.10 | Version v1.05.10 or later | https://www.dell.com/support/home/product-support/product/dell-edge-gateway-5200/drivers |
CVE-2023-32471 | Dell Edge Gateway 5200 | DXE driver | Versions prior to v1.05.10 | Version v1.05.10 or later | https://www.dell.com/support/home/product-support/product/dell-edge-gateway-5200/drivers |
CVE-2023-32471 | Dell Edge Gateway 3200 | DXE driver | Versions prior to v1.03.10 | Version v1.03.10 or later | https://www.dell.com/support/home/product-support/product/dell-edge-gateway-3200/drivers |
Revision | Date | Description |
1.0 | 2023-06-14 | Initial Release |
2.0 | 2023-06-19 | Update |
3.0 | 2023-07-21 | Corrected CVSS vector strings |
All CVEs: Dell Technologies would like to thank the BINARLY efiXplorer team for reporting these issues.
CVE-2023-32467: Dell Technologies would also like to thank yngweijw (Jiawei Yin) for reporting this issue.