LOW · 3.8

CVE-2024-0154

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read...

Vulnerability Description

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.

CVSS Score

3.8

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DellPoweredge R660 Firmware< 2.0.0
DellPoweredge R660-
DellPoweredge R760 Firmware< 2.0.0
DellPoweredge R760-
DellPoweredge C6620 Firmware< 2.0.0
DellPoweredge C6620-
DellPoweredge Mx760C Firmware< 2.0.0
DellPoweredge Mx760C-
DellPoweredge R860 Firmware< 1.8.0
DellPoweredge R860-
DellPoweredge R960 Firmware< 1.8.0
DellPoweredge R960-
DellPoweredge Hs5610 Firmware< 2.0.0
DellPoweredge Hs5610-
DellPoweredge Hs5620 Firmware< 2.0.0
DellPoweredge Hs5620-
DellPoweredge R660Xs Firmware< 2.0.0
DellPoweredge R660Xs-
DellPoweredge R760Xs Firmware< 2.0.0
DellPoweredge R760Xs-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-0154?

CVE-2024-0154 is a vulnerability with a CVSS score of 3.8 (LOW). Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read...

How severe is CVE-2024-0154?

CVE-2024-0154 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-0154?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Poweredge R660 Firmware, Dell Poweredge R660, Dell Poweredge R760 Firmware, Dell Poweredge R760, Dell Poweredge C6620 Firmware.