MEDIUM · 5.3

CVE-2024-0163

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to ot...

Vulnerability Description

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
DellPoweredge R660 Firmware< 2.0.0
DellPoweredge R660-
DellPoweredge R760 Firmware< 2.0.0
DellPoweredge R760-
DellPoweredge C6620 Firmware< 2.0.0
DellPoweredge C6620-
DellPoweredge Mx760C Firmware< 2.0.0
DellPoweredge Mx760C-
DellPoweredge R860 Firmware< 1.8.0
DellPoweredge R860-
DellPoweredge R960 Firmware< 1.8.0
DellPoweredge R960-
DellPoweredge Hs5610 Firmware< 2.0.0
DellPoweredge Hs5610-
DellPoweredge Hs5620 Firmware< 2.0.0
DellPoweredge Hs5620-
DellPoweredge R660Xs Firmware< 2.0.0
DellPoweredge R660Xs-
DellPoweredge R760Xs Firmware< 2.0.0
DellPoweredge R760Xs-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-0163?

CVE-2024-0163 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to ot...

How severe is CVE-2024-0163?

CVE-2024-0163 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-0163?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Poweredge R660 Firmware, Dell Poweredge R660, Dell Poweredge R760 Firmware, Dell Poweredge R760, Dell Poweredge C6620 Firmware.