CVE-2022-34383

HIGH

Dell Edge Gateway 5200 Firmware < 1.03.10 - OS Command Injection via SMI Bypass

Title source: llm
STIX 2.1

Description

Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user may potentially exploit this vulnerability by using an SMI to bypass PMC mitigation and gain arbitrary code execution during SMM.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.dell.com/support/kbdoc/en-us/000202711

Scores

CVSS v3 8.1
EPSS 0.0047
EPSS Percentile 65.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L

Details

CWE
CWE-78 CWE-77
Status published
Products (1)
dell/edge_gateway_5200_firmware < 1.03.10
Published Aug 31, 2022
Tracked Since Feb 18, 2026