CVE-2024-0172

Published Apr 3, 2024

Last updated a year ago

Overview

Description
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
Source
security_alert@emc.com
NVD status
Analyzed
Products
poweredge_r660_firmware, poweredge_r760_firmware, poweredge_c6620_firmware, poweredge_mx760c_firmware, poweredge_r860_firmware, poweredge_r960_firmware, poweredge_hs5610_firmware, poweredge_hs5620_firmware, poweredge_r660xs_firmware, poweredge_r760xs_firmware, poweredge_r760xd2_firmware, poweredge_t560_firmware, poweredge_r760xa_firmware, poweredge_xe9680_firmware, poweredge_xr5610_firmware, poweredge_xr8610t_firmware, poweredge_xr8620t_firmware, poweredge_xr7620_firmware, poweredge_xe8640_firmware, poweredge_xe9640_firmware, poweredge_r6615_firmware, poweredge_r7615_firmware, poweredge_r6625_firmware, poweredge_r7625_firmware, poweredge_r650_firmware, poweredge_r750_firmware, poweredge_r750xa_firmware, poweredge_c6520_firmware, poweredge_mx750c_firmware, poweredge_r550_firmware, poweredge_r450_firmware, poweredge_r650xs_firmware, poweredge_r750xs_firmware, poweredge_t550_firmware, poweredge_xr11_firmware, poweredge_xr12_firmware, poweredge_t150_firmware, poweredge_t350_firmware, poweredge_r250_firmware, poweredge_r350_firmware, poweredge_xr4510c_firmware, poweredge_xr4520c_firmware, poweredge_r6515_firmware, poweredge_r6525_firmware, poweredge_r7515_firmware, poweredge_r7525_firmware, poweredge_c6525_firmware, poweredge_xe8545_firmware, poweredge_r740_firmware, poweredge_r740xd_firmware, poweredge_r640_firmware, poweredge_r940_firmware, poweredge_r540_firmware, poweredge_r440_firmware, poweredge_t440_firmware, poweredge_xr2_firmware, poweredge_r740xd2_firmware, poweredge_r840_firmware, poweredge_r940xa_firmware, poweredge_t640_firmware, poweredge_c6420_firmware, poweredge_fc640_firmware, poweredge_m640_firmware, poweredge_m640_\(pe_vrtx\)_firmware, poweredge_mx740c_firmware, poweredge_mx840c_firmware, poweredge_c4140_firmware, dss_8440_firmware, poweredge_xe2420_firmware, poweredge_xe7420_firmware, poweredge_xe7440_firmware, poweredge_t140_firmware, poweredge_t340_firmware, poweredge_r240_firmware, poweredge_r340_firmware, poweredge_r6415_firmware, poweredge_r7415_firmware, poweredge_r7425_firmware, emc_storage_nx3240_firmware, emc_storage_nx3340_firmware, nx440_firmware, emc_xc_core_xc450_firmware, emc_xc_core_xc650_firmware, emc_xc_core_xc750_firmware, emc_xc_core_xc750xa_firmware, emc_xc_core_xc6520_firmware, emc_xc_core_6420_system_firmware, emc_xc_core_xc640_system_firmware, emc_xc_core_xc740xd_system_firmware, emc_xc_core_xc740xd2_firmware, emc_xc_core_xc940_system_firmware, emc_xc_core_xcxr2_firmware, emc_xc_core_xc7525_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security_alert@emc.com
CWE-269
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations