NA

CVE-2023-25537

Published: 22/05/2023 Updated: 30/05/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Dell PowerEdge 14G server BIOS versions before 2.18.1 and Dell Precision BIOS versions before 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.

Vulnerable Product Search on Vulmon Subscribe to Product

dell poweredge_r740_firmware

dell poweredge_r740xd_firmware

dell poweredge_r640_firmware

dell poweredge_r940_firmware

dell poweredge_r540_firmware

dell poweredge_r440_firmware

dell poweredge_t440_firmware

dell poweredge_xr2_firmware

dell poweredge_r740xd2_firmware

dell poweredge_r840_firmware

dell poweredge_r940xa_firmware

dell poweredge_t640_firmware

dell poweredge_c6420_firmware

dell poweredge_fc640_firmware

dell poweredge_m640_firmware

dell poweredge_mx740c_firmware

dell poweredge_mx840c_firmware

dell poweredge_c4140_firmware

dell dss_8440_firmware

dell poweredge_xe2420_firmware

dell poweredge_xe7420_firmware

dell poweredge_xe7440_firmware

dell emc_storage_nx3240_firmware

dell emc_storage_nx3340_firmware

dell emc_xc_core_6420_firmware

dell emc_xc_core_xc640_firmware

dell emc_xc_core_xc740xd_firmware

dell emc_xc_core_xc740xd2_firmware

dell emc_xc_core_xc940_firmware

dell emc_xc_core_xcxr2_firmware