Show filters
40 Total Results
Displaying 1-10 of 40
Sort by:
Attacker Value
Unknown
CVE-2024-25942
Disclosure Date: March 19, 2024 (last updated February 05, 2025)
Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
0
Attacker Value
Unknown
CVE-2024-22453
Disclosure Date: March 19, 2024 (last updated February 05, 2025)
Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit this vulnerability to write to otherwise unauthorized memory.
0
Attacker Value
Unknown
CVE-2024-0173
Disclosure Date: March 13, 2024 (last updated February 01, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
0
Attacker Value
Unknown
CVE-2024-0154
Disclosure Date: March 13, 2024 (last updated February 01, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
0
Attacker Value
Unknown
CVE-2024-0161
Disclosure Date: March 13, 2024 (last updated February 05, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
0
Attacker Value
Unknown
CVE-2023-32460
Disclosure Date: December 08, 2023 (last updated December 15, 2023)
Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
0
Attacker Value
Unknown
CVE-2023-4608
Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.
This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
0
Attacker Value
Unknown
CVE-2023-4607
Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user can change permissions for any user through a crafted API command.
0
Attacker Value
Unknown
CVE-2023-4606
Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.
This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
0
Attacker Value
Unknown
CVE-2023-25492
Disclosure Date: May 01, 2023 (last updated October 08, 2023)
A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API.
0