Time-of-check Time-of-use Vulnerability in Dell BIOS
CVE-2023-28075

6.9MEDIUM

Key Information:

Vendor
Dell
Status
Vendor
CVE Published:
16 August 2023

Summary

Dell BIOS is susceptible to a Time-of-check Time-of-use vulnerability, which allows local authenticated users with physical access to execute arbitrary code. By exploiting this flaw through a specifically timed Direct Memory Access (DMA) transaction during System Management Interrupt (SMI) events, attackers could gain unauthorized privileges. This poses a significant risk to system integrity and highlights the necessity for rigorous physical security measures.

Affected Version(s)

CPG BIOS All Versions

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.