MEDIUM · 4.4

CVE-2024-25942

Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitra...

Vulnerability Description

Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.

CVSS Score

4.4

MEDIUM

CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
DellPoweredge R730 Firmware< 2.19.0
DellPoweredge R730-
DellPoweredge R730Xd Firmware< 2.19.0
DellPoweredge R730Xd-
DellPoweredge R630 Firmware< 2.19.0
DellPoweredge R630-
DellPoweredge C4130 Firmware< 2.19.0
DellPoweredge C4130-
DellPoweredge R930 Firmware< 2.14.0
DellPoweredge R930-
DellPoweredge M630 Firmware< 2.19.0
DellPoweredge M630-
DellPoweredge M630 \(Pe Vrtx\) Firmware< 2.19.0
DellPoweredge M630 \(Pe Vrtx\)-
DellPoweredge Fc630 Firmware< 2.19.0
DellPoweredge Fc630-
DellPoweredge Fc430 Firmware< 2.19.0
DellPoweredge Fc430-
DellPoweredge M830 Firmware< 2.19.0
DellPoweredge M830-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-25942?

CVE-2024-25942 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitra...

How severe is CVE-2024-25942?

CVE-2024-25942 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-25942?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Poweredge R730 Firmware, Dell Poweredge R730, Dell Poweredge R730Xd Firmware, Dell Poweredge R730Xd, Dell Poweredge R630 Firmware.