Out-of-Bounds Read Vulnerability in Dell Edge Gateway BIOS Could Lead to Stack Memory Access

CVE-2023-32471
6MEDIUM

Key Information

Vendor
Dell
Status
Dell Edge Gateway 5200
Dell Edge Gateway 3200
Vendor
CVE Published:
24 July 2024

Summary

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits.

Affected Version(s)

Dell Edge Gateway 5200 < N/A

Dell Edge Gateway 3200 < N/A

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Dell Technologies would like to thank the BINARLY efiXplorer team for reporting these issues.
.