HIGH · 8.8

CVE-2023-32460

Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. ...

Vulnerability Description

Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DellPoweredge R660 Firmware< 1.6.6
DellPoweredge R660-
DellPoweredge R760 Firmware< 1.6.6
DellPoweredge R760-
DellPoweredge C6620 Firmware< 1.6.6
DellPoweredge C6620-
DellPoweredge Mx760C Firmware< 1.6.6
DellPoweredge Mx760C-
DellPoweredge R860 Firmware< 1.6.6
DellPoweredge R860-
DellPoweredge R960 Firmware< 1.6.6
DellPoweredge R960-
DellPoweredge Hs5610 Firmware< 1.6.6
DellPoweredge Hs5610-
DellPoweredge Hs5620 Firmware< 1.6.6
DellPoweredge Hs5620-
DellPoweredge R660Xs Firmware< 1.6.6
DellPoweredge R660Xs-
DellPoweredge R760Xs Firmware< 1.6.6
DellPoweredge R760Xs-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-32460?

CVE-2023-32460 is a vulnerability with a CVSS score of 8.8 (HIGH). Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. ...

How severe is CVE-2023-32460?

CVE-2023-32460 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-32460?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Poweredge R660 Firmware, Dell Poweredge R660, Dell Poweredge R760 Firmware, Dell Poweredge R760, Dell Poweredge C6620 Firmware.