CVE-2023-32475

HIGH
Published Jun 7, 2024 Modified Nov 21, 2024 CWE-353

Description

Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system.

CVSS v3.1 Score

7.6
HIGH
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weakness Type (CWE)

CWE-353 CWE-353

Affected Products

Vendor Product
dell vostro_5625_firmware
dell vostro_5625
dell vostro_5515_firmware
dell vostro_5515
dell vostro_5415_firmware
dell vostro_5415
dell vostro_3405_firmware
dell vostro_3405
dell vostro_16_5635_firmware
dell vostro_16_5635
dell vostro_15_3535_firmware
dell vostro_15_3535
dell vostro_15_3525_firmware
dell vostro_15_3525
dell vostro_15_3515_firmware
dell vostro_15_3515
dell vostro_14_3435_firmware
dell vostro_14_3435
dell vostro_14_3425_firmware
dell vostro_14_3425
dell inspiron_7415_2-in-1_firmware
dell inspiron_7415_2-in-1
dell inspiron_7405_2-in-1_firmware
dell inspiron_7405_2-in-1
dell inspiron_5515_firmware
dell inspiron_5515
dell inspiron_5505_firmware
dell inspiron_5505
dell inspiron_5415_firmware
dell inspiron_5415
dell inspiron_5405_firmware
dell inspiron_5405
dell inspiron_3505_firmware
dell inspiron_3505
dell inspiron_24_5415_all-in-one_firmware
dell inspiron_24_5415_all-in-one
dell inspiron_16_7635_2-in-1_firmware
dell inspiron_16_7635_2-in-1
dell inspiron_16_5635_firmware
dell inspiron_16_5635
dell inspiron_16_5625_firmware
dell inspiron_16_5625
dell inspiron_15_3535_firmware
dell inspiron_15_3535
dell inspiron_15_3525_firmware
dell inspiron_15_3525
dell inspiron_15_3515_firmware
dell inspiron_15_3515
dell inspiron_14_7435_2-in-1_firmware
dell inspiron_14_7435_2-in-1
dell inspiron_14_7425_2-in-1_firmware
dell inspiron_14_7425_2-in-1
dell inspiron_14_5435_firmware
dell inspiron_14_5435
dell inspiron_14_5425_firmware
dell inspiron_14_5425
dell g5_5505_firmware
dell g5_5505
dell g15_5535_firmware
dell g15_5535
dell g15_5525_firmware
dell g15_5525
dell g15_5515_firmware
dell g15_5515
dell alienware_m18_firmware
dell alienware_m18
dell alienware_m17_r5_amd_firmware
dell alienware_m17_r5_amd
dell alienware_m16_r1_amd_firmware
dell alienware_m16_r1_amd
dell alienware_m15_ryzen_edition_r5_firmware
dell alienware_m15_ryzen_edition_r5
dell alienware_m15_r7_amd_firmware
dell alienware_m15_r7_amd
dell alienware_aurora_ryzen_edition_r14_firmware
dell alienware_aurora_ryzen_edition_r14
dell alienware_aurora_r15_amd_firmware
dell alienware_aurora_r15_amd
dell alienware_aurora_r10_firmware
dell alienware_aurora_r10

References

Frequently Asked Questions

What is CVE-2023-32475? +
Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system. It has a CVSS v3.1 base score of 7.6 (HIGH).
How severe is CVE-2023-32475? +
CVE-2023-32475 has a CVSS v3.1 score of 7.6 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2023-32475? +
CVE-2023-32475 affects products from dell, specifically: alienware_aurora_r10, alienware_aurora_r10_firmware, alienware_aurora_r15_amd, alienware_aurora_r15_amd_firmware, alienware_aurora_ryzen_edition_r14, alienware_aurora_ryzen_edition_r14_firmware, alienware_m15_r7_amd, alienware_m15_r7_amd_firmware, alienware_m15_ryzen_edition_r5, alienware_m15_ryzen_edition_r5_firmware, alienware_m16_r1_amd, alienware_m16_r1_amd_firmware, alienware_m17_r5_amd, alienware_m17_r5_amd_firmware, alienware_m18, alienware_m18_firmware, g15_5515, g15_5515_firmware, g15_5525, g15_5525_firmware, g15_5535, g15_5535_firmware, g5_5505, g5_5505_firmware, inspiron_14_5425, inspiron_14_5425_firmware, inspiron_14_5435, inspiron_14_5435_firmware, inspiron_14_7425_2-in-1, inspiron_14_7425_2-in-1_firmware, inspiron_14_7435_2-in-1, inspiron_14_7435_2-in-1_firmware, inspiron_15_3515, inspiron_15_3515_firmware, inspiron_15_3525, inspiron_15_3525_firmware, inspiron_15_3535, inspiron_15_3535_firmware, inspiron_16_5625, inspiron_16_5625_firmware, inspiron_16_5635, inspiron_16_5635_firmware, inspiron_16_7635_2-in-1, inspiron_16_7635_2-in-1_firmware, inspiron_24_5415_all-in-one, inspiron_24_5415_all-in-one_firmware, inspiron_3505, inspiron_3505_firmware, inspiron_5405, inspiron_5405_firmware, inspiron_5415, inspiron_5415_firmware, inspiron_5505, inspiron_5505_firmware, inspiron_5515, inspiron_5515_firmware, inspiron_7405_2-in-1, inspiron_7405_2-in-1_firmware, inspiron_7415_2-in-1, inspiron_7415_2-in-1_firmware, vostro_14_3425, vostro_14_3425_firmware, vostro_14_3435, vostro_14_3435_firmware, vostro_15_3515, vostro_15_3515_firmware, vostro_15_3525, vostro_15_3525_firmware, vostro_15_3535, vostro_15_3535_firmware, vostro_16_5635, vostro_16_5635_firmware, vostro_3405, vostro_3405_firmware, vostro_5415, vostro_5415_firmware, vostro_5515, vostro_5515_firmware, vostro_5625, vostro_5625_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2023-32475? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2023-32475 — free, no signup required.

Start Free Scan