Out-of-Bounds Read Vulnerability in Dell Edge Gateway BIOS Could Lead to Stack Memory Access
CVE-2023-32471

6MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
24 July 2024

Summary

The Dell Edge Gateway BIOS versions 3200 and 5200 are susceptible to an out-of-bounds read vulnerability. This flaw allows local authenticated users with elevated privileges to read portions of stack memory, potentially leading to further security breaches. Exploiting this vulnerability enables access to sensitive data residing in memory, which malicious actors could leverage for additional attacks. It is essential for users of affected products to implement the recommended security updates to mitigate any risks associated with this vulnerability.

Affected Version(s)

Dell Edge Gateway 3200 < N/A

Dell Edge Gateway 5200 < N/A

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell Technologies would like to thank the BINARLY efiXplorer team for reporting these issues.
.