CVE-2022-22566CWE-1190

Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability

Medium · published February 9, 2022

CVSS v3.1
6.9
EPSS
0%
Percentile
17.2
In the wild
Unconfirmed
What it is

Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.

The record
Technical detail
CVSS v3.1
6.9 · MEDIUM
Vector
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00257 · 17.2th percentile
Weakness
CWE-1190 · DMA Device Enabled Too Early in Boot Phase
Published
2022-02-09T20:00Z
EPSS history
Timeline
  • 09 FEB 20:00Z
    Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability
    cvelistv5