CVE-2023-28026

MEDIUM

Dell Alienware Area 51m R1 Firmware - Improper Input Validation

Title source: rule

Description

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

Scores

CVSS v3 5.1
EPSS 0.0002
EPSS Percentile 4.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L

Classification

CWE
CWE-20
Status published

Affected Products (50)

dell/inspiron_5493_firmware < 1.26.0
dell/inspiron_5494_firmware < 1.23.0
dell/alienware_area_51m_r1_firmware < 1.26.0
dell/alienware_area_51m_r2_firmware < 1.22.0
dell/alienware_aurora_r11_firmware < 1.0.20
dell/alienware_aurora_r12_firmware < 1.1.20
dell/alienware_aurora_r13_firmware < 1.12.0
dell/alienware_aurora_r15_firmware < 1.1.0
dell/alienware_m15_r2_firmware < 1.22.0
dell/alienware_m15_r3_firmware < 1.23.0
dell/alienware_m15_r4_firmware < 1.17.0
dell/alienware_m15_r6_firmware < 1.21.0
dell/alienware_m15_r7_firmware < 1.16.0
dell/alienware_m16_firmware < 1.7.0
dell/alienware_m17_r2_firmware < 1.22.0
... and 35 more

Timeline

Published Jun 23, 2023
Tracked Since Feb 18, 2026