CVE-2024-0162

Published Mar 13, 2024

Last updated a year ago

Overview

Description
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to out-of-bound read/writes to SMRAM.
Source
security_alert@emc.com
NVD status
Analyzed
Products
poweredge_r660_firmware, poweredge_r760_firmware, poweredge_c6620_firmware, poweredge_mx760c_firmware, poweredge_r860_firmware, poweredge_r960_firmware, poweredge_hs5610_firmware, poweredge_hs5620_firmware, poweredge_r660xs_firmware, poweredge_r760xs_firmware, poweredge_r760xd2_firmware, poweredge_t560_firmware, poweredge_r760xa_firmware, poweredge_xe9680_firmware, poweredge_xr5610_firmware, poweredge_xr8610t_firmware, poweredge_xr8620t_firmware, poweredge_xr7620_firmware, poweredge_xe8640_firmware, poweredge_xe9640_firmware, poweredge_r6615_firmware, poweredge_r7615_firmware, poweredge_r6625_firmware, poweredge_r7625_firmware, poweredge_c6615_firmware, poweredge_r650_firmware, poweredge_r750_firmware, poweredge_r750xa_firmware, poweredge_c6520_firmware, poweredge_mx750c_firmware, poweredge_r550_firmware, poweredge_r450_firmware, poweredge_r650xs_firmware, poweredge_r750xs_firmware, poweredge_t550_firmware, poweredge_xr11_firmware, poweredge_xr12_firmware, poweredge_t150_firmware, poweredge_t350_firmware, poweredge_r250_firmware, poweredge_r350_firmware, poweredge_xr4510c_firmware, poweredge_xr4520c_firmware, poweredge_r6515_firmware, poweredge_r6525_firmware, poweredge_r7515_firmware, poweredge_r7525_firmware, poweredge_c6525_firmware, poweredge_xe8545_firmware, xc_core_xc660_firmware, xc_core_xc760_firmware, xc_core_xc7625_firmware, emc_xc_core_xc450_firmware, emc_xc_core_xc650_firmware, emc_xc_core_xc750_firmware, emc_xc_core_xc750xa_firmware, emc_xc_core_xc6520_firmware, emc_xc_core_xc7525_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
6
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security_alert@emc.com
CWE-119
nvd@nist.gov
CWE-787

Social media

Hype score
Not currently trending

Configurations