6.8
CVE-2023-44298
- EPSS 0.24%
- Veröffentlicht 05.12.2023 16:15:07
- Zuletzt bearbeitet 21.11.2024 08:25:37
- Erkennungen
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Poweredge R660 Firmware Version 1.4.4
Dell ≫ Poweredge R760 Firmware Version 1.4.4
Dell ≫ Poweredge C6620 Firmware Version 1.4.4
Dell ≫ Poweredge Mx760c Firmware Version 1.4.4
Dell ≫ Poweredge R860 Firmware Version 1.4.4
Dell ≫ Poweredge R960 Firmware Version 1.4.4
Dell ≫ Poweredge Hs5610 Firmware Version 1.4.4
Dell ≫ Poweredge Hs5620 Firmware Version 1.4.4
Dell ≫ Poweredge R660xs Firmware Version 1.4.4
Dell ≫ Poweredge R760xs Firmware Version 1.4.4
Dell ≫ Poweredge R760xd2 Firmware Version 1.4.4
Dell ≫ Poweredge T560 Firmware Version 1.4.4
Dell ≫ Poweredge R760xa Firmware Version 1.4.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.153 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| EMC | 3.6 | 0.5 | 2.7 |
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
|
CWE-1234 Hardware Internal or Debug Modes Allow Override of Locks
System configuration protection may be bypassed during debug mode.
CWE-667 Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
https://www.dell.com/support/kbdoc/en-us/000220047/dsa-2023-429-security-update-for-dell-16g-poweredge-server-bios-for-a-debug-code-security-vulnerability