CVE-2023-43088
Last modified
CVE-2023-43088 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device. . EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Precision 7865 Tower Firmware | < 1.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-43088?
How severe is CVE-2023-43088?
How do I fix CVE-2023-43088?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-43079 Dell OpenManage Server Administrator, versions 11.0.0.0 and…7.8
- CVE-2023-4308The User Submitted Posts plugin for WordPress is vulnerable …5.4
- CVE-2023-43081 PowerProtect Agent for File System Version 19.14 and prior,…3.3
- CVE-2023-43082 Dell Unity prior to 5.3 contains a 'man in the middle' vuln…5.9
- CVE-2023-43086 Dell Command | Configure, versions prior to 4.11.0, contain…7.8
- CVE-2023-43087 Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an im…6.5
- CVE-2023-43089 Dell Rugged Control Center, version prior to 4.7, contains …3.3
- CVE-2023-4309Election Services Co. (ESC) Internet Election Service is vul…9.8
- CVE-2023-43090A vulnerability was found in GNOME Shell. GNOME Shell's lock…5.5
- CVE-2023-43091A flaw was found in GNOME Maps, which is vulnerable to a cod…9.8
- CVE-2023-4310BeyondTrust Privileged Remote Access (PRA) and Remote Suppor…9.8
- CVE-2023-43102An issue was discovered in Zimbra Collaboration (ZCS) before…6.1
Are you affected by CVE-2023-43088?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
