CVE-2013-3582

UnknownEPSS 2.59%

Last modified

CVE-2013-3582 is a vulnerability of currently unknown severity. Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.. EPSS estimates a 2.59% chance of exploitation in the next 30 days.

Description

Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.

Metrics

EPSS Probability
2.59%

83.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellLatitude D530All versions
DellLatitude D531All versions
DellLatitude D630All versions
DellLatitude D631All versions
DellLatitude D830All versions
DellLatitude E4200All versions
DellLatitude E4300All versions
DellLatitude E5400All versions
DellLatitude E5500All versions
DellLatitude E6400All versions
DellLatitude E6400 AtgAll versions
DellLatitude E6400 Atg XfrAll versions
DellLatitude E6500All versions
DellLatitude Xt2All versions
DellLatitude Z600All versions
DellPrecision M2300All versions
DellPrecision M2400All versions
DellPrecision M4300All versions
DellPrecision M4400All versions
DellPrecision M6300All versions
DellPrecision M6400All versions
DellPrecision M6500All versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-3582?
Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.
How severe is CVE-2013-3582?
Severity scoring for CVE-2013-3582 is pending analysis. The EPSS model estimates a 2.59% probability of exploitation in the next 30 days.
How do I fix CVE-2013-3582?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-3582?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST