CVE Vulnerabilities

CVE-2023-48674

Improper Null Termination

Published: Mar 01, 2024 | Modified: Jan 31, 2025
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.

Weakness

The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.

Affected Software

NameVendorStart VersionEnd Version
Precision_3430_tower_firmwareDell*1.28.0 (excluding)

Potential Mitigations

References