Out-of-Bounds Read Vulnerability in Dell Edge Gateway BIOS Could Lead to Stack Memory Access
CVE-2023-32471
6MEDIUM
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 24 July 2024
Summary
The Dell Edge Gateway BIOS versions 3200 and 5200 are susceptible to an out-of-bounds read vulnerability. This flaw allows local authenticated users with elevated privileges to read portions of stack memory, potentially leading to further security breaches. Exploiting this vulnerability enables access to sensitive data residing in memory, which malicious actors could leverage for additional attacks. It is essential for users of affected products to implement the recommended security updates to mitigate any risks associated with this vulnerability.
Affected Version(s)
Dell Edge Gateway 3200 < N/A
Dell Edge Gateway 5200 < N/A
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell Technologies would like to thank the BINARLY efiXplorer team for reporting these issues.