Input validation error in Aptio V - CVE-2023-39535

 

Input validation error in Aptio V - CVE-2023-39535

Published: November 15, 2023


Vulnerability identifier: #VU83166
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-39535
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient validation of user-supplied input within the UEFI/BIOS firmware. A local user can escalate privileges on the system.


Affected software

Aptio V
Inspiron 15 3521
Inspiron 3502
Inspiron 3510
Inspiron 3482
Inspiron 3782
Vostro 3582
Wyse 5070
Latitude 3190
Latitude 3190 2-In-1

How to mitigate CVE-2023-39535

Install updates from vendor's website.

Inspiron 15 3521 - update to 1.12.0
Inspiron 3502 - update to 1.14.0
Inspiron 3510 - addressed in versions 1.17.0, 1.20.0
Inspiron 3482 - update to 1.20.0
Inspiron 3782 - update to 1.20.0
Vostro 3582 - update to 1.20.0
Wyse 5070 - update to 1.24.0
Latitude 3190 - update to 1.28.0
Latitude 3190 2-In-1 - update to 1.28.0

External References

Related Security Bulletins