CVE-2022-29083

MEDIUM

Dell Chengming 3980 Firmware < 2.23.0 - Unauthenticated Improper Authentication

Title source: llm
STIX 2.1

Description

Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.dell.com/support/kbdoc/000201396

Scores

CVSS v3 6.8
EPSS 0.0011
EPSS Percentile 28.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (50)
dell/chengming_3980_firmware < 2.23.0
dell/chengming_3990_firmware < 1.11.0
dell/chengming_3991_firmware < 1.11.0
Dell/CPG BIOS unspecified - 9-12
dell/g3_3579_firmware < 1.21.0
dell/g3_3779_firmware < 1.21.0
dell/g5_5000_firmware < 1.7.0
dell/g5_5090_firmware < 1.14.0
dell/g5_5587_firmware < 1.21.0
dell/g7_7588_firmware < 1.21.0
... and 40 more
Published Aug 09, 2022
Tracked Since Feb 18, 2026