Unknown
CVE-2023-25537
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2023-25537
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- dss 8440 firmware,
- emc storage nx3240 firmware,
- emc storage nx3340 firmware,
- emc xc core 6420 firmware,
- emc xc core xc640 firmware,
- emc xc core xc740xd firmware,
- emc xc core xc740xd2 firmware,
- emc xc core xc940 firmware,
- emc xc core xcxr2 firmware,
- poweredge c4140 firmware,
- poweredge c6420 firmware,
- poweredge fc640 firmware,
- poweredge m640 firmware,
- poweredge mx740c firmware,
- poweredge mx840c firmware,
- poweredge r440 firmware,
- poweredge r540 firmware,
- poweredge r640 firmware,
- poweredge r740 firmware,
- poweredge r740xd firmware,
- poweredge r740xd2 firmware,
- poweredge r840 firmware,
- poweredge r940 firmware,
- poweredge r940xa firmware,
- poweredge t440 firmware,
- poweredge t640 firmware,
- poweredge xe2420 firmware,
- poweredge xe7420 firmware,
- poweredge xe7440 firmware,
- poweredge xr2 firmware
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: