CVE-2024-0162
13.03.2024, 17:15
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to out-of-bound read/writes to SMRAM.Enginsight
Vendor | Product | Version |
---|---|---|
dell | poweredge_r660_firmware | 𝑥 < 2.0.0 |
dell | poweredge_r760_firmware | 𝑥 < 2.0.0 |
dell | poweredge_c6620_firmware | 𝑥 < 2.0.0 |
dell | poweredge_mx760c_firmware | 𝑥 < 2.0.0 |
dell | poweredge_r860_firmware | 𝑥 < 1.8.0 |
dell | poweredge_r960_firmware | 𝑥 < 1.8.0 |
dell | poweredge_hs5610_firmware | 𝑥 < 2.0.0 |
dell | poweredge_hs5620_firmware | 𝑥 < 2.0.0 |
dell | poweredge_r660xs_firmware | 𝑥 < 2.0.0 |
dell | poweredge_r760xs_firmware | 𝑥 < 2.0.0 |
dell | poweredge_r760xd2_firmware | 𝑥 < 2.0.0 |
dell | poweredge_t560_firmware | 𝑥 < 2.0.0 |
dell | poweredge_r760xa_firmware | 𝑥 < 2.0.0 |
dell | poweredge_xe9680_firmware | 𝑥 < 1.8.0 |
dell | poweredge_xr5610_firmware | 𝑥 < 1.8.0 |
dell | poweredge_xr8610t_firmware | 𝑥 < 1.8.0 |
dell | poweredge_xr8620t_firmware | 𝑥 < 1.8.0 |
dell | poweredge_xr7620_firmware | 𝑥 < 1.8.0 |
dell | poweredge_xe8640_firmware | 𝑥 < 1.8.0 |
dell | poweredge_xe9640_firmware | 𝑥 < 1.8.0 |
dell | poweredge_r6615_firmware | 𝑥 < 1.7.2 |
dell | poweredge_r7615_firmware | 𝑥 < 1.7.2 |
dell | poweredge_r6625_firmware | 𝑥 < 1.7.2 |
dell | poweredge_r7625_firmware | 𝑥 < 1.7.2 |
dell | poweredge_c6615_firmware | 𝑥 < 1.2.3 |
dell | poweredge_r650_firmware | 𝑥 < 1.13.2 |
dell | poweredge_r750_firmware | 𝑥 < 1.13.2 |
dell | poweredge_r750xa_firmware | 𝑥 < 1.13.2 |
dell | poweredge_c6520_firmware | 𝑥 < 1.13.2 |
dell | poweredge_mx750c_firmware | 𝑥 < 1.13.2 |
dell | poweredge_r550_firmware | 𝑥 < 1.13.2 |
dell | poweredge_r450_firmware | 𝑥 < 1.13.2 |
dell | poweredge_r650xs_firmware | 𝑥 < 1.13.2 |
dell | poweredge_r750xs_firmware | 𝑥 < 1.13.2 |
dell | poweredge_t550_firmware | 𝑥 < 1.13.2 |
dell | poweredge_xr11_firmware | 𝑥 < 1.13.2 |
dell | poweredge_xr12_firmware | 𝑥 < 1.13.2 |
dell | poweredge_t150_firmware | 𝑥 < 1.9.1 |
dell | poweredge_t350_firmware | 𝑥 < 1.9.1 |
dell | poweredge_r250_firmware | 𝑥 < 1.9.1 |
dell | poweredge_r350_firmware | 𝑥 < 1.9.1 |
dell | poweredge_xr4510c_firmware | 𝑥 < 1.14.1 |
dell | poweredge_xr4520c_firmware | 𝑥 < 1.14.1 |
dell | poweredge_r6515_firmware | 𝑥 < 2.14.1 |
dell | poweredge_r6525_firmware | 𝑥 < 2.14.1 |
dell | poweredge_r7515_firmware | 𝑥 < 2.14.1 |
dell | poweredge_r7525_firmware | 𝑥 < 2.14.1 |
dell | poweredge_c6525_firmware | 𝑥 < 2.14.1 |
dell | poweredge_xe8545_firmware | 𝑥 < 2.14.1 |
dell | xc_core_xc660_firmware | 𝑥 < 2.0.0 |
dell | xc_core_xc760_firmware | 𝑥 < 2.0.0 |
dell | xc_core_xc7625_firmware | 𝑥 < 1.7.2 |
dell | emc_xc_core_xc450_firmware | 𝑥 < 1.13.2 |
dell | emc_xc_core_xc650_firmware | 𝑥 < 1.13.2 |
dell | emc_xc_core_xc750_firmware | 𝑥 < 1.13.2 |
dell | emc_xc_core_xc750xa_firmware | 𝑥 < 1.13.2 |
dell | emc_xc_core_xc6520_firmware | 𝑥 < 1.13.2 |
dell | emc_xc_core_xc7525_firmware | 𝑥 < 2.14.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-119 - Improper Restriction of Operations within the Bounds of a Memory BufferThe software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.
References