Show filters
80 Total Results
Displaying 1-10 of 80
Sort by:
Attacker Value
Unknown

CVE-2024-0172

Disclosure Date: April 03, 2024 (last updated February 05, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
Attacker Value
Unknown

CVE-2024-0173

Disclosure Date: March 13, 2024 (last updated February 01, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
Attacker Value
Unknown

CVE-2024-0163

Disclosure Date: March 13, 2024 (last updated February 01, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.
Attacker Value
Unknown

CVE-2024-0162

Disclosure Date: March 13, 2024 (last updated February 05, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to out-of-bound read/writes to SMRAM.
Attacker Value
Unknown

CVE-2024-0154

Disclosure Date: March 13, 2024 (last updated February 01, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
Attacker Value
Unknown

CVE-2024-0161

Disclosure Date: March 13, 2024 (last updated February 05, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
Attacker Value
Unknown

CVE-2023-5630

Disclosure Date: December 14, 2023 (last updated December 28, 2023)
A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmware.
Attacker Value
Unknown

CVE-2023-5629

Disclosure Date: December 14, 2023 (last updated December 28, 2023)
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.
Attacker Value
Unknown

CVE-2023-32460

Disclosure Date: December 08, 2023 (last updated December 15, 2023)
Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
Attacker Value
Unknown

CVE-2023-32461

Disclosure Date: September 15, 2023 (last updated October 08, 2023)
Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, leading to corrupt memory and potentially escalate privileges.