CVE-2023-32471
Estado: ModificadaMedia (6)—
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- Puntuación base: 6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (10)
Dell — Edge Gateway 3200 FirmwareDell — Edge Gateway 5200 FirmwareDell — G5 5587 FirmwareDell — G7 7588 FirmwareDell — Inspiron 7460 FirmwareDell — Optiplex 7080 FirmwareDell — Precision 3930 Rack FirmwareDell — Precision 5520 FirmwareDell — Precision 5820 Tower FirmwareDell — Vostro 15 7580 Firmware
CWE
- CWE-125
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-32471",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-32471",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-07-24T18:41:40.675410Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security_alert@emc.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 1.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 1.5
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "Dell",
"product": "Dell Edge Gateway 5200",
"versions": [
{
"status": "affected",
"version": "N/A",
"lessThan": "v1.05.10",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Dell",
"product": "Dell Edge Gateway 3200",
"versions": [
{
"status": "affected",
"version": "N/A",
"lessThan": "v1.03.10",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:h:dell:dell_edge_gateway_5200:*:*:*:*:*:*:*:*"
],
"vendor": "dell",
"product": "dell_edge_gateway_5200",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "v1.05.10",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:2.3:h:dell:dell_edge_gateway_3200:*:*:*:*:*:*:*:*"
],
"vendor": "dell",
"product": "dell_edge_gateway_3200",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "v1.03.10",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-07-24T08:15:02.393",
"references": [
{
"url": "https://www.dell.com/support/kbdoc/en-us/000214917/dsa-2023-225-security-update-for-dell-bios-edge-gateway-5200-and-edge-gateway-3200",
"tags": [
"Vendor Advisory"
],
"source": "security_alert@emc.com"
},
{
"url": "https://www.dell.com/support/kbdoc/en-us/000214917/dsa-2023-225-security-update-for-dell-bios-edge-gateway-5200-and-edge-gateway-3200",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security_alert@emc.com",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits."
},
{
"lang": "es",
"value": "El BIOS de Dell Edge Gateway, versiones 3200 y 5200, contiene una vulnerabilidad de lectura fuera de los límites. Un usuario malintencionado local autenticado con altos privilegios podría explotar esta vulnerabilidad para leer el contenido de la memoria de la pila y utilizar esta información para futuras vulnerabilidades."
}
],
"lastModified": "2026-06-17T05:58:54.780",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:edge_gateway_3200_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44A5114F-DF4F-4E59-9644-079B266D3C7E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:edge_gateway_3200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FBA59414-5A32-4706-85A5-D5459EE22BA5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:edge_gateway_5200_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A33717D-3EF1-4A63-B34A-495EE29ED512"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:edge_gateway_5200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F6832A53-E950-4572-A178-CF5DC14CACC5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:precision_3930_rack_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A07DED87-9B3B-45DE-B9E7-BD1FE4D93C53"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:precision_3930_rack:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1BEC8FAE-1E4E-48A1-8570-5F7A6FE67701"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:optiplex_7080_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6169425-876E-4EFE-8E59-FC3E654774F5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:optiplex_7080:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CC8D3BF8-D39B-4137-AC10-79037CD2B1EF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:precision_5520_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0003FD82-34DB-4443-9661-A2130E23ABB9"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:precision_5520:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CBBFE522-7630-4BED-9B2C-2AC12CA693DE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:inspiron_7460_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "213B78DA-BCD2-4609-A3D4-E1F7043E8AE3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:inspiron_7460:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6FFB8D95-2938-4B40-BA59-32BC194B5DC6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:precision_5820_tower_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "601988B3-86FB-4304-B8C7-3CB37FFCEBE7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:precision_5820_tower:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1C2EC78F-36B6-4B73-96C9-EDC94F4CF4B2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:g5_5587_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C029E28D-DA7E-4CF8-BA0A-0130DBF4188E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:g5_5587:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4274911B-43DC-4827-AB0D-314ACCE5B26A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:g7_7588_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83284EC7-748A-4E0F-83DD-F815CF0FB5D7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:g7_7588:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "269CF69F-0633-461A-A265-AB9728C40DA3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:vostro_15_7580_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "77293B25-DEB9-4FE3-ABA3-517107B668C1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:vostro_15_7580:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "089423B4-E489-4AAD-ABFA-4961DFC26C97"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security_alert@emc.com"
}