PT-2024-2751 · Dell · Dell Poweredge Server Bios+1

Published

2024-04-02

·

Updated

2024-04-12

·

CVE-2024-0172

CVSS v3.1

7.9

High

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Dell PowerEdge Server BIOS (affected versions not specified) Dell Precision Rack BIOS (affected versions not specified)
Description The issue is related to improper privilege management in the BIOS of Dell PowerEdge Server and Dell Precision Rack. An unauthenticated local attacker could potentially exploit this, leading to privilege escalation. This could grant the attacker full control of a vulnerable server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-02880
CVE-2024-0172

Affected Products

Dell Poweredge Server Bios
Dell Precision Rack Bios