Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-3582


Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.


Published

2013-08-28T13:13:58.223

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.6 (HIGH)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

4.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware dell latitude_d530 - Yes
Hardware dell latitude_d531 - Yes
Hardware dell latitude_d630 - Yes
Hardware dell latitude_d631 - Yes
Hardware dell latitude_d830 - Yes
Hardware dell latitude_e4200 - Yes
Hardware dell latitude_e4300 - Yes
Hardware dell latitude_e5400 - Yes
Hardware dell latitude_e5500 - Yes
Hardware dell latitude_e6400 - Yes
Hardware dell latitude_e6400_atg - Yes
Hardware dell latitude_e6400_atg_xfr - Yes
Hardware dell latitude_e6500 - Yes
Hardware dell latitude_xt2 - Yes
Hardware dell latitude_z600 - Yes
Hardware dell precision_m2300 - Yes
Hardware dell precision_m2400 - Yes
Hardware dell precision_m4300 - Yes
Hardware dell precision_m4400 - Yes
Hardware dell precision_m6300 - Yes
Hardware dell precision_m6400 - Yes
Hardware dell precision_m6500 - Yes

References