Show filters
40 Total Results
Displaying 1-10 of 40
Sort by:
Attacker Value
Unknown

CVE-2024-25942

Disclosure Date: March 19, 2024 (last updated February 05, 2025)
Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
Attacker Value
Unknown

CVE-2024-22453

Disclosure Date: March 19, 2024 (last updated February 05, 2025)
Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit this vulnerability to write to otherwise unauthorized memory.
Attacker Value
Unknown

CVE-2024-0173

Disclosure Date: March 13, 2024 (last updated February 01, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
Attacker Value
Unknown

CVE-2024-0154

Disclosure Date: March 13, 2024 (last updated February 01, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
Attacker Value
Unknown

CVE-2024-0161

Disclosure Date: March 13, 2024 (last updated February 05, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
Attacker Value
Unknown

CVE-2023-32460

Disclosure Date: December 08, 2023 (last updated December 15, 2023)
Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
Attacker Value
Unknown

CVE-2023-4608

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-4607

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user can change permissions for any user through a crafted API command.
Attacker Value
Unknown

CVE-2023-4606

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-25492

Disclosure Date: May 01, 2023 (last updated October 08, 2023)
A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API.