ZeroHour

CVE-2022-34383

CVSS 3.1
8.2 high
EPSS
<1%p38
Published
()
Modified
Description

Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentially exploit this vulnerability by using an SMI to bypass PMC mitigation and gain arbitrary code execution during SMM.

Vendors
dell
Products
edge gateway 5200 firmware
Weakness
CWE-77, CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.