Buffer overflow in Dell products - CVE-2022-22558

 

Buffer overflow in Dell products - CVE-2022-22558

Published: January 5, 2023


Vulnerability identifier: #VU70710
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22558
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A local user can create a specially crafted trigger memory corruption and execute arbitrary code on the target system or perform a denial of service attack.


Affected software

Precision Workstation 7910 Rack BIOS
Precision Workstation 7920 Rack BIOS
PowerEdge Server BIOS
Avamar Data Store Gen5A
Integrated System for Microsoft Azure Stack Hub
EMC Integrated Data Protection Appliance

How to mitigate CVE-2022-22558

Install updates from vendor's website.

Integrated System for Microsoft Azure Stack Hub - update to 2210

External References

Related Security Bulletins