Vulnerability Description
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Poweredge R660 Firmware | < 1.5.6 |
| Dell | Poweredge R660 | - |
| Dell | Poweredge R760 Firmware | < 1.5.6 |
| Dell | Poweredge R760 | - |
| Dell | Poweredge C6620 Firmware | < 1.5.6 |
| Dell | Poweredge C6620 | - |
| Dell | Poweredge Mx760C Firmware | < 1.5.6 |
| Dell | Poweredge Mx760C | - |
| Dell | Poweredge R860 Firmware | < 1.5.6 |
| Dell | Poweredge R860 | - |
| Dell | Poweredge R960 Firmware | < 1.5.6 |
| Dell | Poweredge R960 | - |
| Dell | Poweredge Hs5610 Firmware | < 1.5.6 |
| Dell | Poweredge Hs5610 | - |
| Dell | Poweredge Hs5620 Firmware | < 1.5.6 |
| Dell | Poweredge Hs5620 | - |
| Dell | Poweredge R660Xs Firmware | < 1.5.6 |
| Dell | Poweredge R660Xs | - |
| Dell | Poweredge R760Xs Firmware | < 1.5.6 |
| Dell | Poweredge R760Xs | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000223727/dsa-2024-035-security-update-Vendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000223727/dsa-2024-035-security-update-Vendor Advisory
FAQ
What is CVE-2024-0172?
CVE-2024-0172 is a vulnerability with a CVSS score of 7.9 (HIGH). Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability,...
How severe is CVE-2024-0172?
CVE-2024-0172 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0172?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Poweredge R660 Firmware, Dell Poweredge R660, Dell Poweredge R760 Firmware, Dell Poweredge R760, Dell Poweredge C6620 Firmware.