CVE-2024-0161

Published Mar 13, 2024

Last updated a year ago

Overview

Description
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
Source
security_alert@emc.com
NVD status
Analyzed
Products
poweredge_t360_firmware, poweredge_r360_firmware, poweredge_r650_firmware, poweredge_r750_firmware, poweredge_r750xa_firmware, poweredge_c6520_firmware, poweredge_mx750c_firmware, poweredge_r550_firmware, poweredge_r450_firmware, poweredge_r650xs_firmware, poweredge_r750xs_firmware, poweredge_t550_firmware, poweredge_xr11_firmware, poweredge_xr12_firmware, poweredge_xr4510c_firmware, poweredge_xr4520c_firmware, poweredge_t150_firmware, poweredge_t350_firmware, poweredge_r250_firmware, poweredge_r350_firmware, poweredge_r740_firmware, poweredge_r740xd_firmware, poweredge_r640_firmware, poweredge_r940_firmware, poweredge_r540_firmware, poweredge_r440_firmware, poweredge_t440_firmware, poweredge_xr2_firmware, poweredge_r740xd2_firmware, poweredge_r840_firmware, poweredge_r940xa_firmware, poweredge_t640_firmware, poweredge_c6420_firmware, poweredge_fc640_firmware, poweredge_m640_firmware, poweredge_m640_\(pe_vrtx\)_firmware, poweredge_mx740c_firmware, poweredge_mx840c_firmware, poweredge_c4140_firmware, dss_8440_firmware, poweredge_xe2420_firmware, poweredge_xe7420_firmware, poweredge_xe7440_firmware, poweredge_r730_firmware, poweredge_r730xd_firmware, poweredge_r630_firmware, poweredge_c4130_firmware, poweredge_r930_firmware, poweredge_m630_firmware, poweredge_m630_\(pe_vrtx\)_firmware, poweredge_fc630_firmware, poweredge_fc430_firmware, poweredge_m830_firmware, poweredge_m830_\(pe_vrtx\)_firmware, poweredge_fc830_firmware, poweredge_t630_firmware, poweredge_r530_firmware, poweredge_r430_firmware, poweredge_t430_firmware, poweredge_r830_firmware, poweredge_c6320_firmware, poweredge_t130_firmware, poweredge_r230_firmware, poweredge_t330_firmware, poweredge_r330_firmware, emc_storage_nx3240_firmware, emc_storage_nx3340_firmware, storage_nx3230_firmware, storage_nx3330_firmware, storage_nx430_firmware, emc_xc_core_xc450_firmware, emc_xc_core_xc650_firmware, emc_xc_core_xc750_firmware, emc_xc_core_xc750xa_firmware, emc_xc_core_xc6520_firmware, emc_xc_core_6420_firmware, emc_xc_core_xc640_firmware, emc_xc_core_xc740xd_firmware, emc_xc_core_xc740xd2_firmware, emc_xc_core_xc940_firmware, emc_xc_core_xcxr2_firmware, xc6320_firmware, xc430_firmware, xc630_firmware, xc730_firmware, xc730xd_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
8.4
Impact score
5.8
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Severity
HIGH

Weaknesses

security_alert@emc.com
CWE-20
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations