BIOS Vulnerability Allows Arbitrary Code Execution with Physical Access
CVE-2023-32475

7.6HIGH

Key Information:

Vendor
Dell
Status
Vendor
CVE Published:
7 June 2024

Summary

Dell BIOS has a vulnerability due to the absence of support for integrity checks, which allows an attacker with physical access to the system to bypass existing security mechanisms. This vulnerability could potentially enable the execution of arbitrary code on the affected system, posing significant risks to data integrity and system security.

Affected Version(s)

CPG BIOS < 2.6.0

CPG BIOS < 1.13.0

CPG BIOS < 1.15.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.