CVE-2023-48674
Last modified
CVE-2023-48674 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Precision 3430 Tower Firmware | < 1.28.0 |
| Dell | Precision 3431 Tower Firmware | < 1.24.0 |
| Dell | Precision 3630 Tower Firmware | < 2.26.0 |
| Dell | Precision 5820 Tower Firmware | < 2.34.0 |
| Dell | Precision 7820 Tower Firmware | < 2.38.0 |
| Dell | Precision 7920 Tower Firmware | < 2.38.0 |
| Dell | Latitude 5280 Firmware | < 1.34.0 |
| Dell | Latitude 5288 Firmware | < 1.34.0 |
| Dell | Latitude 5290 Firmware | < 1.33.0 |
| Dell | Latitude 5290 2-In-1 Firmware | < 1.32.0 |
| Dell | Latitude 5300 Firmware | < 1.29.0 |
| Dell | Latitude 5300 2-In-1 Firmware | < 1.29.0 |
| Dell | Latitude 5310 Firmware | < 1.22.0 |
| Dell | Latitude 5310 2-In-1 Firmware | < 1.22.0 |
| Dell | Latitude 5320 Firmware | < 1.36.0 |
| Dell | Latitude 5330 Firmware | < 1.19.0 |
| Dell | Latitude 5340 Firmware | < 1.10.1 |
| Dell | Latitude 5400 Firmware | < 1.28.0 |
| Dell | Latitude 5401 Firmware | < 1.29.0 |
| Dell | Latitude 5410 Firmware | < 1.25.0 |
| Dell | Latitude 5411 Firmware | < 1.26.0 |
| Dell | Latitude 5420 Firmware | < 1.36.2 |
| Dell | Latitude 5420 Rugged Firmware | < 1.30.0 |
| Dell | Latitude 5421 Firmware | < 1.27.1 |
| Dell | Latitude 5424 Rugged Firmware | < 1.30.0 |
| Dell | Latitude 5430 Firmware | < 1.19.0 |
| Dell | Latitude 5430 Rugged Laptop Firmware | < 1.24.0 |
| Dell | Latitude 5431 Firmware | < 1.19.0 |
| Dell | Latitude 5440 Firmware | < 1.11.0 |
| Dell | Latitude 5480 Firmware | < 1.34.0 |
| Dell | Latitude 5488 Firmware | < 1.34.0 |
| Dell | Latitude 5490 Firmware | < 1.33.0 |
| Dell | Latitude 5491 Firmware | < 1.31.0 |
| Dell | Latitude 5500 Firmware | < 1.28.0 |
| Dell | Latitude 5501 Firmware | < 1.29.0 |
| Dell | Latitude 5510 Firmware | < 1.25.0 |
| Dell | Latitude 5511 Firmware | < 1.26.0 |
| Dell | Latitude 5520 Firmware | < 1.36.0 |
| Dell | Latitude 5521 Firmware | < 1.28.0 |
| Dell | Latitude 5530 Firmware | < 1.21.1 |
| Dell | Latitude 5531 Firmware | < 1.20.0 |
| Dell | Latitude 5540 Firmware | < 1.10.1 |
| Dell | Latitude 5580 Firmware | < 1.34.0 |
| Dell | Latitude 5590 Firmware | < 1.33.0 |
| Dell | Latitude 5591 Firmware | < 1.31.0 |
| Dell | Latitude 7200 2-In-1 Firmware | < 1.27.0 |
| Dell | Latitude 7210 2-In-1 Firmware | < 1.27.0 |
| Dell | Latitude 7212 Rugged Extreme Tablet Firmware | < 1.48.0 |
| Dell | Latitude 7220 Rugged Extreme Firmware | < 1.34.1 |
| Dell | Latitude 7230 Rugged Extreme Firmware | < 1.12.0 |
Showing 50 of 174 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-48674?
How severe is CVE-2023-48674?
How do I fix CVE-2023-48674?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-48665 Dell vApp Manager, versions prior to 9.2.4.x contain a comm…7.2
- CVE-2023-48667 Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.…7.2
- CVE-2023-48668 Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.…6.7
- CVE-2023-4867A vulnerability was found in Xintian Smart Table Integrated …8.8
- CVE-2023-48670 Dell SupportAssist for Home PCs version 3.14.1 and prior ve…7.8
- CVE-2023-48671 Dell vApp Manager, versions prior to 9.2.4.x contain an inf…7.5
- CVE-2023-48676Sensitive information disclosure and manipulation due to mis…7.1
- CVE-2023-48677Local privilege escalation due to DLL hijacking vulnerabilit…7.8
- CVE-2023-48678Sensitive information disclosure due to insecure folder perm…5.5
- CVE-2023-48679Stored cross-site scripting (XSS) vulnerability due to missi…5.4
- CVE-2023-4868A vulnerability was found in SourceCodester Contact Manager …8.8
- CVE-2023-48680Sensitive information disclosure due to excessive collection…5.5
Are you affected by CVE-2023-48674?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
