Vulnerability Description
Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit this vulnerability to write to otherwise unauthorized memory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Poweredge R730 Firmware | < 2.19.0 |
| Dell | Poweredge R730 | - |
| Dell | Poweredge R730Xd Firmware | < 2.19.0 |
| Dell | Poweredge R730Xd | - |
| Dell | Poweredge R630 Firmware | < 2.19.0 |
| Dell | Poweredge R630 | - |
| Dell | Poweredge C4130 Firmware | < 2.19.0 |
| Dell | Poweredge C4130 | - |
| Dell | Poweredge R930 Firmware | < 2.14.0 |
| Dell | Poweredge R930 | - |
| Dell | Poweredge M630 Firmware | < 2.19.0 |
| Dell | Poweredge M630 | - |
| Dell | Poweredge M630 \(Pe Vrtx\) Firmware | < 2.19.0 |
| Dell | Poweredge M630 \(Pe Vrtx\) | - |
| Dell | Poweredge Fc630 Firmware | < 2.19.0 |
| Dell | Poweredge Fc630 | - |
| Dell | Poweredge Fc430 Firmware | < 2.19.0 |
| Dell | Poweredge Fc430 | - |
| Dell | Poweredge M830 Firmware | < 2.19.0 |
| Dell | Poweredge M830 | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000223209/dsa-2024-105-security-update-Vendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000223209/dsa-2024-105-security-update-Vendor Advisory
FAQ
What is CVE-2024-22453?
CVE-2024-22453 is a vulnerability with a CVSS score of 7.2 (HIGH). Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit this vulnerability to write to otherwise unauthorized memory.
How severe is CVE-2024-22453?
CVE-2024-22453 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22453?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Poweredge R730 Firmware, Dell Poweredge R730, Dell Poweredge R730Xd Firmware, Dell Poweredge R730Xd, Dell Poweredge R630 Firmware.