CVE-2022-26861
Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution during SMM.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.9
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
- EPSS probability
- 0.04%
- CWE
- CWE-1038
- Published
- 2022-09-06
- Last modified
- 2026-05-27
Affected products
- Dell CPG BIOS
Weakness type
Related vulnerabilities
- CVE-2025-48877 — Discourse vulnerable to auto-executing of third-party code in embedded CodePen iframe
- CVE-2023-52971 — MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in...
- CVE-2023-52970 — MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*,...
- CVE-2023-52969 — MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through...
- CVE-2022-31220 — Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated...