CVE-2022-29083
Last modified
CVE-2022-29083 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Chengming 3980 Firmware | < 2.23.0 |
| Dell | Chengming 3990 Firmware | < 1.11.0 |
| Dell | Chengming 3991 Firmware | < 1.11.0 |
| Dell | G3 3579 Firmware | < 1.21.0 |
| Dell | G3 3779 Firmware | < 1.21.0 |
| Dell | G5 5587 Firmware | < 1.21.0 |
| Dell | G5 5000 Firmware | < 1.7.0 |
| Dell | G5 5090 Firmware | < 1.14.0 |
| Dell | G7 7588 Firmware | < 1.21.0 |
| Dell | Inspiron 3470 Firmware | < 2.23.0 |
| Dell | Inspiron 3480 Firmware | < 1.19.0 |
| Dell | Inspiron 3493 Firmware | < 1.19.0 |
| Dell | Inspiron 3501 Firmware | < 1.11.0 |
| Dell | Inspiron 3580 Firmware | < 1.19.0 |
| Dell | Inspiron 3593 Firmware | < 1.19.0 |
| Dell | Inspiron 3670 Firmware | < 2.23.0 |
| Dell | Inspiron 3780 Firmware | < 1.19.0 |
| Dell | Inspiron 3790 Firmware | < 1.16.0 |
| Dell | Inspiron 3793 Firmware | < 1.19.0 |
| Dell | Inspiron 3880 Firmware | < 1.11.0 |
| Dell | Inspiron 3881 Firmware | < 1.11.0 |
| Dell | Inspiron 5310 Firmware | < 2.6.1 |
| Dell | Inspiron 5410 Firmware | < 2.6.1 |
| Dell | Inspiron 5493 Firmware | < 1.19.0 |
| Dell | Inspiron 5494 Firmware | < 1.16.0 |
| Dell | Inspiron 5510 Firmware | < 2.6.1 |
| Dell | Inspiron 5593 Firmware | < 1.19.0 |
| Dell | Inspiron 5594 Firmware | < 1.16.0 |
| Dell | Inspiron 7490 Firmware | < 1.11.0 |
| Dell | Inspiron 7510 Firmware | < 1.4.0 |
| Dell | Inspiron 7610 Firmware | < 1.4.0 |
| Dell | Latitude 3120 Firmware | < 1.9.2 |
| Dell | Latitude 3190 Firmware | < 1.21.1 |
| Dell | Latitude 3320 Firmware | < 1.8.2 |
| Dell | Latitude 5310 Firmware | < 1.9.1 |
| Dell | Latitude 5410 Firmware | < 1.8.1 |
| Dell | Latitude 5411 Firmware | < 1.8.1 |
| Dell | Latitude 5491 Firmware | < 1.21.1 |
| Dell | Latitude 5510 Firmware | < 1.8.1 |
| Dell | Latitude 5511 Firmware | < 1.8.1 |
| Dell | Latitude 5591 Firmware | < 1.21.1 |
| Dell | Latitude 7210 Firmware | < 1.9.1 |
| Dell | Latitude 7310 Firmware | < 1.9.1 |
| Dell | Latitude 7410 Firmware | < 1.9.1 |
| Dell | Latitude 9410 Firmware | < 1.9.1 |
| Dell | Latitude 9510 Firmware | < 1.8.1 |
| Dell | Optiplex 3060 Firmware | < 1.20.0 |
| Dell | Optiplex 3070 Firmware | < 1.15.0 |
| Dell | Optiplex 3080 Firmware | < 2.11.0 |
| Dell | Optiplex 3090 Firmware | < 2.4.0 |
Showing 50 of 108 affected configurations. See NVD for the full list.
References
- https://www.dell.com/support/kbdoc/000201396Vendor Advisory
- https://www.dell.com/support/kbdoc/000201396Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29083?
How severe is CVE-2022-29083?
How do I fix CVE-2022-29083?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-29077A heap-based buffer overflow exists in rippled before 1.8.5.…9.8
- CVE-2022-29078The ejs (aka Embedded JavaScript templates) package 3.1.6 fo…9.8
- CVE-2022-2908A potential DoS vulnerability was discovered in Gitlab CE/EE…4.3
- CVE-2022-29080The npm-dependency-versions package through 0.3.0 for Node.j…9.8
- CVE-2022-29081Zoho ManageEngine Access Manager Plus before 4302, Password …9.8
- CVE-2022-29082Dell EMC NetWorker versions 19.1.x, 19.1.0.x, 19.1.1.x, 19.2…4.6
- CVE-2022-29084Dell Unity, Dell UnityVSA, and Dell Unity XT versions before…9.8
- CVE-2022-29085Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior …6.7
- CVE-2022-29086Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-29087Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-29088Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-29089Dell Networking OS10, versions prior to October 2021 with Sm…4.9
Are you affected by CVE-2022-29083?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
