6.7
CVE-2023-32461
- EPSS 0.07%
- Published 15.09.2023 07:15:09
- Last modified 21.11.2024 08:03:23
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, leading to corrupt memory and potentially escalate privileges.
Data is provided by the National Vulnerability Database (NVD)
Dell ≫ Poweredge R660 Firmware Version < 1.5.6
Dell ≫ Poweredge R760 Firmware Version < 1.5.6
Dell ≫ Poweredge C6620 Firmware Version < 1.5.6
Dell ≫ Poweredge Mx760c Firmware Version < 1.5.6
Dell ≫ Poweredge R860 Firmware Version < 1.5.6
Dell ≫ Poweredge R960 Firmware Version < 1.5.6
Dell ≫ Poweredge Hs5610 Firmware Version < 1.5.6
Dell ≫ Poweredge Hs5620 Firmware Version < 1.5.6
Dell ≫ Poweredge R660xs Firmware Version < 1.5.6
Dell ≫ Poweredge R760xs Firmware Version < 1.5.6
Dell ≫ Poweredge R760xd2 Firmware Version < 1.5.6
Dell ≫ Poweredge T560 Firmware Version < 1.5.6
Dell ≫ Poweredge R760xa Firmware Version < 1.1.3
Dell ≫ Poweredge Xe9680 Firmware Version < 1.1.3
Dell ≫ Poweredge Xr5610 Firmware Version < 1.1.4
Dell ≫ Poweredge Xr8620t Firmware Version < 1.1.3
Dell ≫ Poweredge Xr7620 Firmware Version < 1.5.6
Dell ≫ Poweredge Xe8640 Firmware Version < 1.2.5
Dell ≫ Poweredge R6615 Firmware Version < 1.3.11
Dell ≫ Poweredge R7615 Firmware Version < 1.3.11
Dell ≫ Poweredge R6625 Firmware Version < 1.3.11
Dell ≫ Poweredge R7625 Firmware Version < 1.3.11
Dell ≫ Poweredge R650 Firmware Version < 1.10.2
Dell ≫ Poweredge R750 Firmware Version < 1.10.2
Dell ≫ Poweredge R750xa Firmware Version < 1.10.2
Dell ≫ Poweredge C6520 Firmware Version < 1.10.2
Dell ≫ Poweredge Mx750c Firmware Version < 1.10.2
Dell ≫ Poweredge R550 Firmware Version < 1.10.2
Dell ≫ Poweredge R450 Firmware Version < 1.10.2
Dell ≫ Poweredge R650xs Firmware Version < 1.10.2
Dell ≫ Poweredge R750xs Firmware Version < 1.10.2
Dell ≫ Poweredge T550 Firmware Version < 1.10.2
Dell ≫ Poweredge Xr11 Firmware Version < 1.10.2
Dell ≫ Poweredge Xr12 Firmware Version < 1.10.2
Dell ≫ Poweredge T150 Firmware Version < 1.6.3
Dell ≫ Poweredge T350 Firmware Version < 1.6.3
Dell ≫ Poweredge R250 Firmware Version < 1.6.3
Dell ≫ Poweredge R350 Firmware Version < 1.6.3
Dell ≫ Poweredge Xr4510c Firmware Version < 1.10.4
Dell ≫ Poweredge Xr4520c Firmware Version < 1.10.4
Dell ≫ Poweredge Xr4520c Firmware Version1.10.4
Dell ≫ Poweredge R6515 Firmware Version < 2.11.4
Dell ≫ Poweredge R6525 Firmware Version < 2.11.3
Dell ≫ Poweredge R7515 Firmware Version < 2.11.4
Dell ≫ Poweredge R7525 Firmware Version < 2.11.3
Dell ≫ Poweredge C6525 Firmware Version < 2.11.3
Dell ≫ Poweredge Xe8545 Firmware Version < 2.11.3
Dell ≫ Emc Xc Core Xc450 Firmware Version < 1.11.2
Dell ≫ Emc Xc Core Xc650 Firmware Version < 1.11.2
Dell ≫ Emc Xc Core Xc750 Firmware Version < 1.11.2
Dell ≫ Emc Xc Core Xc750xa Firmware Version < 1.11.2
Dell ≫ Emc Xc Core Xc6520 Firmware Version < 1.11.2
Dell ≫ Emc Xc Core Xc7525 Firmware Version < 2.11.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.206 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
security_alert@emc.com | 5 | 0.8 | 3.7 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
|
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().