Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HDell Edge Gateway 3000
HWDellall versionsDell Edge Gateway 3000 Firmware
OSDell< 1.18.0Dell Edge Gateway 5000
HWDellall versionsDell Edge Gateway 5000 Firmware
OSDell< 1.28.0Dell Embedded Box Pc 3000
HWDellall versionsDell Embedded Box Pc 3000 Firmware
OSDell< 1.24.0Dell Embedded Box Pc 5000
HWDellall versionsDell Embedded Box Pc 5000 Firmware
OSDell< 1.25.0Dell Latitude 12 Rugged Extreme 7214
HWDellall versionsDell Latitude 12 Rugged Extreme 7214 Firmware
OSDell< 1.46.0Dell Latitude 13 3380
HWDellall versionsDell Latitude 13 3380 Firmware
OSDell< 1.27.0Dell Latitude 3180
HWDellall versionsDell Latitude 3180 Firmware
OSDell< 1.29.0Dell Latitude 3189
HWDellall versionsDell Latitude 3189 Firmware
OSDell< 1.29.0Dell Latitude 3190
HWDellall versionsDell Latitude 3190 2 In 1
HWDellall versionsDell Latitude 3190 2 In 1 Firmware
OSDell< 1.34.0Dell Latitude 3190 Firmware
OSDell< 1.34.0Dell Latitude 3300
HWDellall versionsDell Latitude 3300 Firmware
OSDell< 1.28.0Dell Latitude 3390 2 In 1
HWDellall versionsDell Latitude 3390 2 In 1 Firmware
OSDell< 1.31.0Dell Latitude 5280
HWDellall versionsDell Latitude 5280 Firmware
OSDell< 1.36.0Dell Latitude 5288
HWDellall versionsDell Latitude 5288 Firmware
OSDell< 1.36.0Dell Latitude 5290
HWDellall versionsDell Latitude 5290 2 In 1
HWDellall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2020-29491CRITICAL10.0PL ✓same product
Dell Wyse ThinOS — niebezpieczna domyślna konfiguracja umożliwia nieautoryzowany dostęp
CVE-2020-29492CRITICAL10.0PL ✓same product
Dell Wyse ThinOS — niezabezpieczona domyślna konfiguracja umożliwia nieautoryzowany dostęp
CVE-2021-21551HIGH8.8⚠ KEVsame product
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation ...
CVE-2025-36600HIGH8.2same product
Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vu...
CVE-2024-52541HIGH8.2same product
Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local ...