Vulnerability CVE-2022-22567


Published: 2022-02-09

Description:
Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware.

Type:

CWE-345

(Insufficient Verification of Data Authenticity)

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.6/10
4.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
Partial

 References:
https://www.dell.com/support/kbdoc/en-us/000195905/dsa-2022-028

Copyright 2022, cxsecurity.com

 

Back to Top