Buffer overflow in Dell products - CVE-2022-22558
Published: January 5, 2023
Vulnerability identifier: #VU70710
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22558
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A local user can create a specially crafted trigger memory corruption and execute arbitrary code on the target system or perform a denial of service attack.
Affected software
Precision Workstation 7910 Rack BIOS
Precision Workstation 7920 Rack BIOS
PowerEdge Server BIOS
Avamar Data Store Gen5A
Integrated System for Microsoft Azure Stack Hub
EMC Integrated Data Protection Appliance
Precision Workstation 7920 Rack BIOS
PowerEdge Server BIOS
Avamar Data Store Gen5A
Integrated System for Microsoft Azure Stack Hub
EMC Integrated Data Protection Appliance
How to mitigate CVE-2022-22558
Install updates from vendor's website.
Integrated System for Microsoft Azure Stack Hub - update to 2210