Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25537


Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.


Published

2023-05-22T11:15:09.333

Last Modified

2024-11-21T07:49:41.453

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dell poweredge_r740_firmware < 2.18.1 Yes
Hardware dell poweredge_r740 - No
Operating System dell poweredge_r740xd_firmware < 2.18.1 Yes
Hardware dell poweredge_r740xd - No
Operating System dell poweredge_r640_firmware < 2.18.1 Yes
Hardware dell poweredge_r640 - No
Operating System dell poweredge_r940_firmware < 2.18.1 Yes
Hardware dell poweredge_r940 - No
Operating System dell poweredge_r540_firmware < 2.18.1 Yes
Hardware dell poweredge_r540 - No
Operating System dell poweredge_r440_firmware < 2.18.1 Yes
Hardware dell poweredge_r440 - No
Operating System dell poweredge_t440_firmware < 2.18.1 Yes
Hardware dell poweredge_t440 - No
Operating System dell poweredge_xr2_firmware < 2.18.1 Yes
Hardware dell poweredge_xr2 - No
Operating System dell poweredge_r740xd2_firmware < 2.18.1 Yes
Hardware dell poweredge_r740xd2 - No
Operating System dell poweredge_r840_firmware < 2.18.1 Yes
Hardware dell poweredge_r840 - No
Operating System dell poweredge_r940xa_firmware < 2.18.1 Yes
Hardware dell poweredge_r940xa - No
Operating System dell poweredge_t640_firmware < 2.18.1 Yes
Hardware dell poweredge_t640 - No
Operating System dell poweredge_c6420_firmware < 2.18.1 Yes
Hardware dell poweredge_c6420 - No
Operating System dell poweredge_fc640_firmware < 2.18.1 Yes
Hardware dell poweredge_fc640 - No
Operating System dell poweredge_m640_firmware < 2.18.1 Yes
Hardware dell poweredge_m640 - No
Operating System dell poweredge_mx740c_firmware < 2.18.1 Yes
Hardware dell poweredge_mx740c - No
Operating System dell poweredge_mx840c_firmware < 2.18.1 Yes
Hardware dell poweredge_mx840c - No
Operating System dell poweredge_c4140_firmware < 2.18.1 Yes
Hardware dell poweredge_c4140 - No
Operating System dell dss_8440_firmware < 2.18.1 Yes
Hardware dell dss_8440 - No
Operating System dell poweredge_xe2420_firmware < 2.18.1 Yes
Hardware dell poweredge_xe2420 - No
Operating System dell poweredge_xe7420_firmware < 2.18.1 Yes
Hardware dell poweredge_xe7420 - No
Operating System dell poweredge_xe7440_firmware < 2.18.1 Yes
Hardware dell poweredge_xe7440 - No
Operating System dell emc_storage_nx3240_firmware < 2.18.1 Yes
Hardware dell emc_storage_nx3240 - No
Operating System dell emc_storage_nx3340_firmware < 2.18.1 Yes
Hardware dell emc_storage_nx3340 - No
Operating System dell emc_xc_core_6420_firmware < 2.18.1 Yes
Hardware dell emc_xc_core_6420 - No
Operating System dell emc_xc_core_xc640_firmware < 2.18.1 Yes
Hardware dell emc_xc_core_xc640 - No
Operating System dell emc_xc_core_xc740xd_firmware < 2.18.1 Yes
Hardware dell emc_xc_core_xc740xd - No
Operating System dell emc_xc_core_xc740xd2_firmware < 2.18.1 Yes
Hardware dell emc_xc_core_xc740xd2 - No
Operating System dell emc_xc_core_xc940_firmware < 2.18.1 Yes
Hardware dell emc_xc_core_xc940 - No
Operating System dell emc_xc_core_xcxr2_firmware < 2.18.1 Yes
Hardware dell emc_xc_core_xcxr2 - No

References