MEDIUM · 6.1

CVE-2023-25537

Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could pote...

Vulnerability Description

Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
DellPoweredge R740 Firmware< 2.18.1
DellPoweredge R740-
DellPoweredge R740Xd Firmware< 2.18.1
DellPoweredge R740Xd-
DellPoweredge R640 Firmware< 2.18.1
DellPoweredge R640-
DellPoweredge R940 Firmware< 2.18.1
DellPoweredge R940-
DellPoweredge R540 Firmware< 2.18.1
DellPoweredge R540-
DellPoweredge R440 Firmware< 2.18.1
DellPoweredge R440-
DellPoweredge T440 Firmware< 2.18.1
DellPoweredge T440-
DellPoweredge Xr2 Firmware< 2.18.1
DellPoweredge Xr2-
DellPoweredge R740Xd2 Firmware< 2.18.1
DellPoweredge R740Xd2-
DellPoweredge R840 Firmware< 2.18.1
DellPoweredge R840-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-25537?

CVE-2023-25537 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could pote...

How severe is CVE-2023-25537?

CVE-2023-25537 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-25537?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Poweredge R740 Firmware, Dell Poweredge R740, Dell Poweredge R740Xd Firmware, Dell Poweredge R740Xd, Dell Poweredge R640 Firmware.