CVE-2022-29083

MEDIUMCVSS 6.8/10EPSS 0.36%

Last modified

CVE-2022-29083 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.

Description

Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.36%

27.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellChengming 3980 Firmware< 2.23.0
DellChengming 3990 Firmware< 1.11.0
DellChengming 3991 Firmware< 1.11.0
DellG3 3579 Firmware< 1.21.0
DellG3 3779 Firmware< 1.21.0
DellG5 5587 Firmware< 1.21.0
DellG5 5000 Firmware< 1.7.0
DellG5 5090 Firmware< 1.14.0
DellG7 7588 Firmware< 1.21.0
DellInspiron 3470 Firmware< 2.23.0
DellInspiron 3480 Firmware< 1.19.0
DellInspiron 3493 Firmware< 1.19.0
DellInspiron 3501 Firmware< 1.11.0
DellInspiron 3580 Firmware< 1.19.0
DellInspiron 3593 Firmware< 1.19.0
DellInspiron 3670 Firmware< 2.23.0
DellInspiron 3780 Firmware< 1.19.0
DellInspiron 3790 Firmware< 1.16.0
DellInspiron 3793 Firmware< 1.19.0
DellInspiron 3880 Firmware< 1.11.0
DellInspiron 3881 Firmware< 1.11.0
DellInspiron 5310 Firmware< 2.6.1
DellInspiron 5410 Firmware< 2.6.1
DellInspiron 5493 Firmware< 1.19.0
DellInspiron 5494 Firmware< 1.16.0
DellInspiron 5510 Firmware< 2.6.1
DellInspiron 5593 Firmware< 1.19.0
DellInspiron 5594 Firmware< 1.16.0
DellInspiron 7490 Firmware< 1.11.0
DellInspiron 7510 Firmware< 1.4.0
DellInspiron 7610 Firmware< 1.4.0
DellLatitude 3120 Firmware< 1.9.2
DellLatitude 3190 Firmware< 1.21.1
DellLatitude 3320 Firmware< 1.8.2
DellLatitude 5310 Firmware< 1.9.1
DellLatitude 5410 Firmware< 1.8.1
DellLatitude 5411 Firmware< 1.8.1
DellLatitude 5491 Firmware< 1.21.1
DellLatitude 5510 Firmware< 1.8.1
DellLatitude 5511 Firmware< 1.8.1
DellLatitude 5591 Firmware< 1.21.1
DellLatitude 7210 Firmware< 1.9.1
DellLatitude 7310 Firmware< 1.9.1
DellLatitude 7410 Firmware< 1.9.1
DellLatitude 9410 Firmware< 1.9.1
DellLatitude 9510 Firmware< 1.8.1
DellOptiplex 3060 Firmware< 1.20.0
DellOptiplex 3070 Firmware< 1.15.0
DellOptiplex 3080 Firmware< 2.11.0
DellOptiplex 3090 Firmware< 2.4.0

Showing 50 of 108 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-29083?
Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.
How severe is CVE-2022-29083?
CVE-2022-29083 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.36% probability of exploitation in the next 30 days.
How do I fix CVE-2022-29083?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-29083?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST