6.3
CVE-2024-0163
- EPSS 0.07%
- Published 13.03.2024 17:15:46
- Last modified 31.01.2025 16:13:51
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.
Data is provided by the National Vulnerability Database (NVD)
Dell ≫ Poweredge R660 Firmware Version < 2.0.0
Dell ≫ Poweredge R760 Firmware Version < 2.0.0
Dell ≫ Poweredge C6620 Firmware Version < 2.0.0
Dell ≫ Poweredge Mx760c Firmware Version < 2.0.0
Dell ≫ Poweredge R860 Firmware Version < 1.8.0
Dell ≫ Poweredge R960 Firmware Version < 1.8.0
Dell ≫ Poweredge Hs5610 Firmware Version < 2.0.0
Dell ≫ Poweredge Hs5620 Firmware Version < 2.0.0
Dell ≫ Poweredge R660xs Firmware Version < 2.0.0
Dell ≫ Poweredge R760xs Firmware Version < 2.0.0
Dell ≫ Poweredge R760xd2 Firmware Version < 2.0.0
Dell ≫ Poweredge T560 Firmware Version < 2.0.0
Dell ≫ Poweredge R760xa Firmware Version < 2.0.0
Dell ≫ Poweredge Xe9680 Firmware Version < 1.8.0
Dell ≫ Poweredge Xr5610 Firmware Version < 1.8.0
Dell ≫ Poweredge Xr8610t Firmware Version < 1.8.0
Dell ≫ Poweredge Xr8620t Firmware Version < 1.8.0
Dell ≫ Poweredge Xr7620 Firmware Version < 1.8.0
Dell ≫ Poweredge Xe8640 Firmware Version < 1.8.0
Dell ≫ Poweredge Xe9640 Firmware Version < 1.8.0
Dell ≫ Poweredge R6615 Firmware Version < 1.7.2
Dell ≫ Poweredge R7615 Firmware Version < 1.7.2
Dell ≫ Poweredge R6625 Firmware Version < 1.7.2
Dell ≫ Poweredge R7625 Firmware Version < 1.7.2
Dell ≫ Poweredge C6615 Firmware Version < 1.2.3
Dell ≫ Poweredge R650 Firmware Version < 1.13.2
Dell ≫ Poweredge R750 Firmware Version < 1.13.2
Dell ≫ Poweredge R750xa Firmware Version < 1.13.2
Dell ≫ Poweredge C6520 Firmware Version < 1.13.2
Dell ≫ Poweredge Mx750c Firmware Version < 1.13.2
Dell ≫ Poweredge R550 Firmware Version < 1.13.2
Dell ≫ Poweredge R450 Firmware Version < 1.13.2
Dell ≫ Poweredge R650xs Firmware Version < 1.13.2
Dell ≫ Poweredge R750xs Firmware Version < 1.13.2
Dell ≫ Poweredge T550 Firmware Version < 1.13.2
Dell ≫ Poweredge Xr11 Firmware Version < 1.13.2
Dell ≫ Poweredge Xr12 Firmware Version < 1.13.2
Dell ≫ Poweredge T150 Firmware Version < 1.9.1
Dell ≫ Poweredge T350 Firmware Version < 1.9.1
Dell ≫ Poweredge R250 Firmware Version < 1.9.1
Dell ≫ Poweredge R350 Firmware Version < 1.9.1
Dell ≫ Poweredge Xr4510c Firmware Version < 1.14.1
Dell ≫ Poweredge Xr4520c Firmware Version < 1.14.1
Dell ≫ Poweredge R6515 Firmware Version < 2.14.1
Dell ≫ Poweredge R6525 Firmware Version < 2.14.1
Dell ≫ Poweredge R7515 Firmware Version < 2.14.1
Dell ≫ Poweredge R7525 Firmware Version < 2.14.1
Dell ≫ Poweredge C6525 Firmware Version < 2.14.1
Dell ≫ Poweredge Xe8545 Firmware Version < 2.14.1
Dell ≫ Xc Core Xc660 Firmware Version < 2.0.0
Dell ≫ Xc Core Xc760 Firmware Version < 2.0.0
Dell ≫ Xc Core Xc7625 Firmware Version < 1.7.2
Dell ≫ Emc Xc Core Xc450 Firmware Version < 1.13.2
Dell ≫ Emc Xc Core Xc650 Firmware Version < 1.13.2
Dell ≫ Emc Xc Core Xc750 Firmware Version < 1.13.2
Dell ≫ Emc Xc Core Xc750xa Firmware Version < 1.13.2
Dell ≫ Emc Xc Core Xc6520 Firmware Version < 1.13.2
Dell ≫ Emc Xc Core Xc7525 Firmware Version < 2.14.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.225 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.3 | 1 | 5.2 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
|
security_alert@emc.com | 5.3 | 1.1 | 3.7 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
|
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.