6.8

CVE-2023-44298

Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Poweredge R660 Firmware Version 1.4.4
   Dell ≫ Poweredge R660 Version -
Dell ≫ Poweredge R760 Firmware Version 1.4.4
   Dell ≫ Poweredge R760 Version -
Dell ≫ Poweredge C6620 Firmware Version 1.4.4
   Dell ≫ Poweredge C6620 Version -
Dell ≫ Poweredge Mx760c Firmware Version 1.4.4
   Dell ≫ Poweredge Mx760c Version -
Dell ≫ Poweredge R860 Firmware Version 1.4.4
   Dell ≫ Poweredge R860 Version -
Dell ≫ Poweredge R960 Firmware Version 1.4.4
   Dell ≫ Poweredge R960 Version -
Dell ≫ Poweredge Hs5610 Firmware Version 1.4.4
   Dell ≫ Poweredge Hs5610 Version -
Dell ≫ Poweredge Hs5620 Firmware Version 1.4.4
   Dell ≫ Poweredge Hs5620 Version -
Dell ≫ Poweredge R660xs Firmware Version 1.4.4
   Dell ≫ Poweredge R660xs Version -
Dell ≫ Poweredge R760xs Firmware Version 1.4.4
   Dell ≫ Poweredge R760xs Version -
Dell ≫ Poweredge R760xd2 Firmware Version 1.4.4
   Dell ≫ Poweredge R760xd2 Version -
Dell ≫ Poweredge T560 Firmware Version 1.4.4
   Dell ≫ Poweredge T560 Version -
Dell ≫ Poweredge R760xa Firmware Version 1.4.4
   Dell ≫ Poweredge R760xa Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.153
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EMC 3.6 0.5 2.7
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
CWE-1234 Hardware Internal or Debug Modes Allow Override of Locks

System configuration protection may be bypassed during debug mode.

CWE-667 Improper Locking

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

https://www.dell.com/support/kbdoc/en-us/000220047/dsa-2023-429-security-update-for-dell-16g-poweredge-server-bios-for-a-debug-code-security-vulnerability
Vendor Advisory