CVE-2023-25537
22.05.2023, 11:15
Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.Enginsight
Vendor | Product | Version |
---|---|---|
dell | poweredge_r740_firmware | 𝑥 < 2.18.1 |
dell | poweredge_r740xd_firmware | 𝑥 < 2.18.1 |
dell | poweredge_r640_firmware | 𝑥 < 2.18.1 |
dell | poweredge_r940_firmware | 𝑥 < 2.18.1 |
dell | poweredge_r540_firmware | 𝑥 < 2.18.1 |
dell | poweredge_r440_firmware | 𝑥 < 2.18.1 |
dell | poweredge_t440_firmware | 𝑥 < 2.18.1 |
dell | poweredge_xr2_firmware | 𝑥 < 2.18.1 |
dell | poweredge_r740xd2_firmware | 𝑥 < 2.18.1 |
dell | poweredge_r840_firmware | 𝑥 < 2.18.1 |
dell | poweredge_r940xa_firmware | 𝑥 < 2.18.1 |
dell | poweredge_t640_firmware | 𝑥 < 2.18.1 |
dell | poweredge_c6420_firmware | 𝑥 < 2.18.1 |
dell | poweredge_fc640_firmware | 𝑥 < 2.18.1 |
dell | poweredge_m640_firmware | 𝑥 < 2.18.1 |
dell | poweredge_mx740c_firmware | 𝑥 < 2.18.1 |
dell | poweredge_mx840c_firmware | 𝑥 < 2.18.1 |
dell | poweredge_c4140_firmware | 𝑥 < 2.18.1 |
dell | dss_8440_firmware | 𝑥 < 2.18.1 |
dell | poweredge_xe2420_firmware | 𝑥 < 2.18.1 |
dell | poweredge_xe7420_firmware | 𝑥 < 2.18.1 |
dell | poweredge_xe7440_firmware | 𝑥 < 2.18.1 |
dell | emc_storage_nx3240_firmware | 𝑥 < 2.18.1 |
dell | emc_storage_nx3340_firmware | 𝑥 < 2.18.1 |
dell | emc_xc_core_6420_firmware | 𝑥 < 2.18.1 |
dell | emc_xc_core_xc640_firmware | 𝑥 < 2.18.1 |
dell | emc_xc_core_xc740xd_firmware | 𝑥 < 2.18.1 |
dell | emc_xc_core_xc740xd2_firmware | 𝑥 < 2.18.1 |
dell | emc_xc_core_xc940_firmware | 𝑥 < 2.18.1 |
dell | emc_xc_core_xcxr2_firmware | 𝑥 < 2.18.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References