Cyber Resilience

CVE-2023-28075

Race Condition in Dell Precision 5820 Tower Firmware ≤ 2.31.0

Published
16 August 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.9
Click a component to see what it means
Raw vectorCVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0017 6th percentile
Risk Priority 48 floored blend · peak EPSS

Summary

CVE-2023-28075 is a medium-severity Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) vulnerability in Dell Precision 5820 Tower Firmware. Its CVSS base score is 6.9 (Medium).

Operationally, ranked at the 6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary…

more

code execution on the system.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-0163Same vendor: Dell
CVE-2026-22281Same vendor: Dell
CVE-2025-30101Same vendor: Dell
CVE-2024-53289Same vendor: Dell
CVE-2025-22394Same vendor: Dell
CVE-2023-28050Same product: Dell Alienware M15 R7
CVE-2023-28041Same product: Dell Alienware M15 R7
CVE-2023-28026Same product: Dell Alienware M15 R7
CVE-2023-28029Same product: Dell Alienware M15 R7
CVE-2023-25936Same product: Dell Alienware M15 R7

Affected Assets

dell
alienware m15 r7 firmware
≤ 1.18.0
dell
alienware m16 firmware
≤ 1.10.1
dell
alienware m18 firmware
≤ 1.10.1
dell
chengming 3900 firmware
≤ 1.15.0
dell
chengming 3901 firmware
≤ 1.15.0
dell
chengming 3910 firmware
≤ 1.6.0
dell
chengming 3911 firmware
≤ 1.6.0
dell
chengming 3980 firmware
≤ 2.32.0
dell
chengming 3990 firmware
≤ 1.21.0
dell
chengming 3991 firmware
≤ 1.21.0
+232 more product configuration(s) — see NVD for full list

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V15.4.2
  • V17.2.6

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-367

Timestamps meeting UTC or offset standards help identify TOCTOU issues through precise chronological reconstruction of check/use operations.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly include coding standards and reviews that prevent TOCTOU race conditions.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

none

Reliable, synchronized time across systems narrows the exploitable window in which a resource state can change between a security check and its use.

References