PT-2024-2242 · Dell · Dell Poweredge Server Bios+1

Published

2024-03-12

·

Updated

2024-04-02

·

CVE-2024-0162

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerEdge Server BIOS (affected versions not specified) Dell Precision Rack BIOS (affected versions not specified)
Description The issue is related to an Improper SMM communication buffer verification vulnerability in the BIOS of Dell PowerEdge Server and Dell Precision Rack. A local low privileged attacker could potentially exploit this vulnerability, leading to out-of-bound read/writes to SMRAM. This could allow an attacker to write arbitrary data to the System Management RAM.
Recommendations For Dell PowerEdge Server BIOS, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Dell Precision Rack BIOS, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-02175
CVE-2024-0162

Affected Products

Dell Poweredge Server Bios
Dell Precision Rack Bios