Vulnerability Description
Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Poweredge R740 Firmware | < 2.18.1 |
| Dell | Poweredge R740 | - |
| Dell | Poweredge R740Xd Firmware | < 2.18.1 |
| Dell | Poweredge R740Xd | - |
| Dell | Poweredge R640 Firmware | < 2.18.1 |
| Dell | Poweredge R640 | - |
| Dell | Poweredge R940 Firmware | < 2.18.1 |
| Dell | Poweredge R940 | - |
| Dell | Poweredge R540 Firmware | < 2.18.1 |
| Dell | Poweredge R540 | - |
| Dell | Poweredge R440 Firmware | < 2.18.1 |
| Dell | Poweredge R440 | - |
| Dell | Poweredge T440 Firmware | < 2.18.1 |
| Dell | Poweredge T440 | - |
| Dell | Poweredge Xr2 Firmware | < 2.18.1 |
| Dell | Poweredge Xr2 | - |
| Dell | Poweredge R740Xd2 Firmware | < 2.18.1 |
| Dell | Poweredge R740Xd2 | - |
| Dell | Poweredge R840 Firmware | < 2.18.1 |
| Dell | Poweredge R840 | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000213550/dsa-2023-098-security-update-Vendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000213550/dsa-2023-098-security-update-Vendor Advisory
FAQ
What is CVE-2023-25537?
CVE-2023-25537 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could pote...
How severe is CVE-2023-25537?
CVE-2023-25537 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25537?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Poweredge R740 Firmware, Dell Poweredge R740, Dell Poweredge R740Xd Firmware, Dell Poweredge R740Xd, Dell Poweredge R640 Firmware.