Description

Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.

Published: 2023-05-22
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-29489 Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
History

Tue, 21 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Dell Dss 8440 Dss 8440 Firmware Emc Storage Nx3240 Emc Storage Nx3240 Firmware Emc Storage Nx3340 Emc Storage Nx3340 Firmware Emc Xc Core 6420 Emc Xc Core 6420 Firmware Emc Xc Core Xc640 Emc Xc Core Xc640 Firmware Emc Xc Core Xc740xd Emc Xc Core Xc740xd2 Emc Xc Core Xc740xd2 Firmware Emc Xc Core Xc740xd Firmware Emc Xc Core Xc940 Emc Xc Core Xc940 Firmware Emc Xc Core Xcxr2 Emc Xc Core Xcxr2 Firmware Poweredge C4140 Poweredge C4140 Firmware Poweredge C6420 Poweredge C6420 Firmware Poweredge Fc640 Poweredge Fc640 Firmware Poweredge M640 Poweredge M640 Firmware Poweredge Mx740c Poweredge Mx740c Firmware Poweredge Mx840c Poweredge Mx840c Firmware Poweredge R440 Poweredge R440 Firmware Poweredge R540 Poweredge R540 Firmware Poweredge R640 Poweredge R640 Firmware Poweredge R740 Poweredge R740 Firmware Poweredge R740xd Poweredge R740xd2 Poweredge R740xd2 Firmware Poweredge R740xd Firmware Poweredge R840 Poweredge R840 Firmware Poweredge R940 Poweredge R940 Firmware Poweredge R940xa Poweredge R940xa Firmware Poweredge T440 Poweredge T440 Firmware Poweredge T640 Poweredge T640 Firmware Poweredge Xe2420 Poweredge Xe2420 Firmware Poweredge Xe7420 Poweredge Xe7420 Firmware Poweredge Xe7440 Poweredge Xe7440 Firmware Poweredge Xr2 Poweredge Xr2 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2025-01-21T15:07:54.481Z

Reserved: 2023-02-07T09:35:27.079Z

Link: CVE-2023-25537

cve-icon Vulnrichment

Updated: 2024-08-02T11:25:18.634Z

cve-icon NVD

Status : Modified

Published: 2023-05-22T11:15:09.333

Modified: 2024-11-21T07:49:41.453

Link: CVE-2023-25537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses