8.8

CVE-2024-0162

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to out-of-bound read/writes to SMRAM.

Data is provided by the National Vulnerability Database (NVD)
DellPoweredge R660 Firmware Version < 2.0.0
   DellPoweredge R660 Version-
DellPoweredge R760 Firmware Version < 2.0.0
   DellPoweredge R760 Version-
DellPoweredge C6620 Firmware Version < 2.0.0
   DellPoweredge C6620 Version-
DellPoweredge Mx760c Firmware Version < 2.0.0
   DellPoweredge Mx760c Version-
DellPoweredge R860 Firmware Version < 1.8.0
   DellPoweredge R860 Version-
DellPoweredge R960 Firmware Version < 1.8.0
   DellPoweredge R960 Version-
DellPoweredge Hs5610 Firmware Version < 2.0.0
   DellPoweredge Hs5610 Version-
DellPoweredge Hs5620 Firmware Version < 2.0.0
   DellPoweredge Hs5620 Version-
DellPoweredge R660xs Firmware Version < 2.0.0
   DellPoweredge R660xs Version-
DellPoweredge R760xs Firmware Version < 2.0.0
   DellPoweredge R760xs Version-
DellPoweredge R760xd2 Firmware Version < 2.0.0
   DellPoweredge R760xd2 Version-
DellPoweredge T560 Firmware Version < 2.0.0
   DellPoweredge T560 Version-
DellPoweredge R760xa Firmware Version < 2.0.0
   DellPoweredge R760xa Version-
DellPoweredge Xe9680 Firmware Version < 1.8.0
   DellPoweredge Xe9680 Version-
DellPoweredge Xr5610 Firmware Version < 1.8.0
   DellPoweredge Xr5610 Version-
DellPoweredge Xr8610t Firmware Version < 1.8.0
   DellPoweredge Xr8610t Version-
DellPoweredge Xr8620t Firmware Version < 1.8.0
   DellPoweredge Xr8620t Version-
DellPoweredge Xr7620 Firmware Version < 1.8.0
   DellPoweredge Xr7620 Version-
DellPoweredge Xe8640 Firmware Version < 1.8.0
   DellPoweredge Xe8640 Version-
DellPoweredge Xe9640 Firmware Version < 1.8.0
   DellPoweredge Xe9640 Version-
DellPoweredge R6615 Firmware Version < 1.7.2
   DellPoweredge R6615 Version-
DellPoweredge R7615 Firmware Version < 1.7.2
   DellPoweredge R7615 Version-
DellPoweredge R6625 Firmware Version < 1.7.2
   DellPoweredge R6625 Version-
DellPoweredge R7625 Firmware Version < 1.7.2
   DellPoweredge R7625 Version-
DellPoweredge C6615 Firmware Version < 1.2.3
   DellPoweredge C6615 Version-
DellPoweredge R650 Firmware Version < 1.13.2
   DellPoweredge R650 Version-
DellPoweredge R750 Firmware Version < 1.13.2
   DellPoweredge R750 Version-
DellPoweredge R750xa Firmware Version < 1.13.2
   DellPoweredge R750xa Version-
DellPoweredge C6520 Firmware Version < 1.13.2
   DellPoweredge C6520 Version-
DellPoweredge Mx750c Firmware Version < 1.13.2
   DellPoweredge Mx750c Version-
DellPoweredge R550 Firmware Version < 1.13.2
   DellPoweredge R550 Version-
DellPoweredge R450 Firmware Version < 1.13.2
   DellPoweredge R450 Version-
DellPoweredge R650xs Firmware Version < 1.13.2
   DellPoweredge R650xs Version-
DellPoweredge R750xs Firmware Version < 1.13.2
   DellPoweredge R750xs Version-
DellPoweredge T550 Firmware Version < 1.13.2
   DellPoweredge T550 Version-
DellPoweredge Xr11 Firmware Version < 1.13.2
   DellPoweredge Xr11 Version-
DellPoweredge Xr12 Firmware Version < 1.13.2
   DellPoweredge Xr12 Version-
DellPoweredge T150 Firmware Version < 1.9.1
   DellPoweredge T150 Version-
DellPoweredge T350 Firmware Version < 1.9.1
   DellPoweredge T350 Version-
DellPoweredge R250 Firmware Version < 1.9.1
   DellPoweredge R250 Version-
DellPoweredge R350 Firmware Version < 1.9.1
   DellPoweredge R350 Version-
DellPoweredge Xr4510c Firmware Version < 1.14.1
   DellPoweredge Xr4510c Version-
DellPoweredge Xr4520c Firmware Version < 1.14.1
   DellPoweredge Xr4520c Version-
DellPoweredge R6515 Firmware Version < 2.14.1
   DellPoweredge R6515 Version-
DellPoweredge R6525 Firmware Version < 2.14.1
   DellPoweredge R6525 Version-
DellPoweredge R7515 Firmware Version < 2.14.1
   DellPoweredge R7515 Version-
DellPoweredge R7525 Firmware Version < 2.14.1
   DellPoweredge R7525 Version-
DellPoweredge C6525 Firmware Version < 2.14.1
   DellPoweredge C6525 Version-
DellPoweredge Xe8545 Firmware Version < 2.14.1
   DellPoweredge Xe8545 Version-
DellXc Core Xc660 Firmware Version < 2.0.0
   DellXc Core Xc660 Version-
DellXc Core Xc760 Firmware Version < 2.0.0
   DellXc Core Xc760 Version-
DellXc Core Xc7625 Firmware Version < 1.7.2
   DellXc Core Xc7625 Version-
DellEmc Xc Core Xc450 Firmware Version < 1.13.2
   DellEmc Xc Core Xc450 Version-
DellEmc Xc Core Xc650 Firmware Version < 1.13.2
   DellEmc Xc Core Xc650 Version-
DellEmc Xc Core Xc750 Firmware Version < 1.13.2
   DellEmc Xc Core Xc750 Version-
DellEmc Xc Core Xc750xa Firmware Version < 1.13.2
   DellEmc Xc Core Xc750xa Version-
DellEmc Xc Core Xc6520 Firmware Version < 1.13.2
   DellEmc Xc Core Xc6520 Version-
DellEmc Xc Core Xc7525 Firmware Version < 2.14.1
   DellEmc Xc Core Xc7525 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.266
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
security_alert@emc.com 5.3 1.1 3.7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.