Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
Metrics
No CVSS v4.0
Attack Vector Local
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact None
Integrity Impact Low
Availability Impact High
User Interaction None
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
The EPSS score is 0.00034.
Exploitation none
Automatable no
Technical Impact total
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Dell
Subscribe
|
Dss 8440
Subscribe
Dss 8440 Firmware
Subscribe
Emc Storage Nx3240
Subscribe
Emc Storage Nx3240 Firmware
Subscribe
Emc Storage Nx3340
Subscribe
Emc Storage Nx3340 Firmware
Subscribe
Emc Xc Core 6420
Subscribe
Emc Xc Core 6420 Firmware
Subscribe
Emc Xc Core Xc640
Subscribe
Emc Xc Core Xc640 Firmware
Subscribe
Emc Xc Core Xc740xd
Subscribe
Emc Xc Core Xc740xd2
Subscribe
Emc Xc Core Xc740xd2 Firmware
Subscribe
Emc Xc Core Xc740xd Firmware
Subscribe
Emc Xc Core Xc940
Subscribe
Emc Xc Core Xc940 Firmware
Subscribe
Emc Xc Core Xcxr2
Subscribe
Emc Xc Core Xcxr2 Firmware
Subscribe
Poweredge C4140
Subscribe
Poweredge C4140 Firmware
Subscribe
Poweredge C6420
Subscribe
Poweredge C6420 Firmware
Subscribe
Poweredge Fc640
Subscribe
Poweredge Fc640 Firmware
Subscribe
Poweredge M640
Subscribe
Poweredge M640 Firmware
Subscribe
Poweredge Mx740c
Subscribe
Poweredge Mx740c Firmware
Subscribe
Poweredge Mx840c
Subscribe
Poweredge Mx840c Firmware
Subscribe
Poweredge R440
Subscribe
Poweredge R440 Firmware
Subscribe
Poweredge R540
Subscribe
Poweredge R540 Firmware
Subscribe
Poweredge R640
Subscribe
Poweredge R640 Firmware
Subscribe
Poweredge R740
Subscribe
Poweredge R740 Firmware
Subscribe
Poweredge R740xd
Subscribe
Poweredge R740xd2
Subscribe
Poweredge R740xd2 Firmware
Subscribe
Poweredge R740xd Firmware
Subscribe
Poweredge R840
Subscribe
Poweredge R840 Firmware
Subscribe
Poweredge R940
Subscribe
Poweredge R940 Firmware
Subscribe
Poweredge R940xa
Subscribe
Poweredge R940xa Firmware
Subscribe
Poweredge T440
Subscribe
Poweredge T440 Firmware
Subscribe
Poweredge T640
Subscribe
Poweredge T640 Firmware
Subscribe
Poweredge Xe2420
Subscribe
Poweredge Xe2420 Firmware
Subscribe
Poweredge Xe7420
Subscribe
Poweredge Xe7420 Firmware
Subscribe
Poweredge Xe7440
Subscribe
Poweredge Xe7440 Firmware
Subscribe
Poweredge Xr2
Subscribe
Poweredge Xr2 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
Configuration 26 [-]
| AND |
|
Configuration 27 [-]
| AND |
|
Configuration 28 [-]
| AND |
|
Configuration 29 [-]
| AND |
|
Configuration 30 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29489 | Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 21 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2025-01-21T15:07:54.481Z
Reserved: 2023-02-07T09:35:27.079Z
Link: CVE-2023-25537
Updated: 2024-08-02T11:25:18.634Z
Status : Modified
Published: 2023-05-22T11:15:09.333
Modified: 2024-11-21T07:49:41.453
Link: CVE-2023-25537
No data.
OpenCVE Enrichment
No data.
EUVD