VDB
CVE-2013-3582
CVE-2013-3582
PUBLISHED
CVSS 7.599999904632568 HIGH
Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.
EPSS 0.84% · 75.1th percentile
Risk Scores
CVSS 2.0
7.599999904632568
EPSS Score
0.84%
75.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| dell | precision_m6500 | |
| dell | precision_m4300 | |
| dell | precision_m4400 | |
| dell | latitude_z600 | |
| dell | latitude_e4300 | |
| dell | latitude_d630 | |
| dell | latitude_e6400 | |
| dell | latitude_e5400 | |
| dell | precision_m2400 | |
| dell | precision_m6300 | |
| dell | latitude_e6500 | |
| n/a | n/a | n/a |
| dell | precision_m6400 | |
| dell | latitude_xt2 | |
| dell | latitude_d631 | |
| dell | latitude_d531 | |
| dell | latitude_e6400_atg | |
| dell | latitude_e6400_atg_xfr | |
| dell | latitude_e4200 | |
| dell | latitude_e5500 |
…and 4 more
Timeline
- Aug 28, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 17, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- VU#912156 third-party-advisory
- https://www.blackhat.com/us-13/archives.html#Butterworth url
- https://media.blackhat.com/us-13/US-13-Butterworth-BIOS-Security-Slides.pdf url
- https://media.blackhat.com/us-13/US-13-Butterworth-BIOS-Security-WP.pdf url
- http://www.kb.cert.org/vuls/id/BLUU-99HSLA url
- https://nvd.nist.gov/vuln/detail/CVE-2013-3582 advisory