6.3

CVE-2024-0163

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.

Data is provided by the National Vulnerability Database (NVD)
DellPoweredge R660 Firmware Version < 2.0.0
   DellPoweredge R660 Version-
DellPoweredge R760 Firmware Version < 2.0.0
   DellPoweredge R760 Version-
DellPoweredge C6620 Firmware Version < 2.0.0
   DellPoweredge C6620 Version-
DellPoweredge Mx760c Firmware Version < 2.0.0
   DellPoweredge Mx760c Version-
DellPoweredge R860 Firmware Version < 1.8.0
   DellPoweredge R860 Version-
DellPoweredge R960 Firmware Version < 1.8.0
   DellPoweredge R960 Version-
DellPoweredge Hs5610 Firmware Version < 2.0.0
   DellPoweredge Hs5610 Version-
DellPoweredge Hs5620 Firmware Version < 2.0.0
   DellPoweredge Hs5620 Version-
DellPoweredge R660xs Firmware Version < 2.0.0
   DellPoweredge R660xs Version-
DellPoweredge R760xs Firmware Version < 2.0.0
   DellPoweredge R760xs Version-
DellPoweredge R760xd2 Firmware Version < 2.0.0
   DellPoweredge R760xd2 Version-
DellPoweredge T560 Firmware Version < 2.0.0
   DellPoweredge T560 Version-
DellPoweredge R760xa Firmware Version < 2.0.0
   DellPoweredge R760xa Version-
DellPoweredge Xe9680 Firmware Version < 1.8.0
   DellPoweredge Xe9680 Version-
DellPoweredge Xr5610 Firmware Version < 1.8.0
   DellPoweredge Xr5610 Version-
DellPoweredge Xr8610t Firmware Version < 1.8.0
   DellPoweredge Xr8610t Version-
DellPoweredge Xr8620t Firmware Version < 1.8.0
   DellPoweredge Xr8620t Version-
DellPoweredge Xr7620 Firmware Version < 1.8.0
   DellPoweredge Xr7620 Version-
DellPoweredge Xe8640 Firmware Version < 1.8.0
   DellPoweredge Xe8640 Version-
DellPoweredge Xe9640 Firmware Version < 1.8.0
   DellPoweredge Xe9640 Version-
DellPoweredge R6615 Firmware Version < 1.7.2
   DellPoweredge R6615 Version-
DellPoweredge R7615 Firmware Version < 1.7.2
   DellPoweredge R7615 Version-
DellPoweredge R6625 Firmware Version < 1.7.2
   DellPoweredge R6625 Version-
DellPoweredge R7625 Firmware Version < 1.7.2
   DellPoweredge R7625 Version-
DellPoweredge C6615 Firmware Version < 1.2.3
   DellPoweredge C6615 Version-
DellPoweredge R650 Firmware Version < 1.13.2
   DellPoweredge R650 Version-
DellPoweredge R750 Firmware Version < 1.13.2
   DellPoweredge R750 Version-
DellPoweredge R750xa Firmware Version < 1.13.2
   DellPoweredge R750xa Version-
DellPoweredge C6520 Firmware Version < 1.13.2
   DellPoweredge C6520 Version-
DellPoweredge Mx750c Firmware Version < 1.13.2
   DellPoweredge Mx750c Version-
DellPoweredge R550 Firmware Version < 1.13.2
   DellPoweredge R550 Version-
DellPoweredge R450 Firmware Version < 1.13.2
   DellPoweredge R450 Version-
DellPoweredge R650xs Firmware Version < 1.13.2
   DellPoweredge R650xs Version-
DellPoweredge R750xs Firmware Version < 1.13.2
   DellPoweredge R750xs Version-
DellPoweredge T550 Firmware Version < 1.13.2
   DellPoweredge T550 Version-
DellPoweredge Xr11 Firmware Version < 1.13.2
   DellPoweredge Xr11 Version-
DellPoweredge Xr12 Firmware Version < 1.13.2
   DellPoweredge Xr12 Version-
DellPoweredge T150 Firmware Version < 1.9.1
   DellPoweredge T150 Version-
DellPoweredge T350 Firmware Version < 1.9.1
   DellPoweredge T350 Version-
DellPoweredge R250 Firmware Version < 1.9.1
   DellPoweredge R250 Version-
DellPoweredge R350 Firmware Version < 1.9.1
   DellPoweredge R350 Version-
DellPoweredge Xr4510c Firmware Version < 1.14.1
   DellPoweredge Xr4510c Version-
DellPoweredge Xr4520c Firmware Version < 1.14.1
   DellPoweredge Xr4520c Version-
DellPoweredge R6515 Firmware Version < 2.14.1
   DellPoweredge R6515 Version-
DellPoweredge R6525 Firmware Version < 2.14.1
   DellPoweredge R6525 Version-
DellPoweredge R7515 Firmware Version < 2.14.1
   DellPoweredge R7515 Version-
DellPoweredge R7525 Firmware Version < 2.14.1
   DellPoweredge R7525 Version-
DellPoweredge C6525 Firmware Version < 2.14.1
   DellPoweredge C6525 Version-
DellPoweredge Xe8545 Firmware Version < 2.14.1
   DellPoweredge Xe8545 Version-
DellXc Core Xc660 Firmware Version < 2.0.0
   DellXc Core Xc660 Version-
DellXc Core Xc760 Firmware Version < 2.0.0
   DellXc Core Xc760 Version-
DellXc Core Xc7625 Firmware Version < 1.7.2
   DellXc Core Xc7625 Version-
DellEmc Xc Core Xc450 Firmware Version < 1.13.2
   DellEmc Xc Core Xc450 Version-
DellEmc Xc Core Xc650 Firmware Version < 1.13.2
   DellEmc Xc Core Xc650 Version-
DellEmc Xc Core Xc750 Firmware Version < 1.13.2
   DellEmc Xc Core Xc750 Version-
DellEmc Xc Core Xc750xa Firmware Version < 1.13.2
   DellEmc Xc Core Xc750xa Version-
DellEmc Xc Core Xc6520 Firmware Version < 1.13.2
   DellEmc Xc Core Xc6520 Version-
DellEmc Xc Core Xc7525 Firmware Version < 2.14.1
   DellEmc Xc Core Xc7525 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.225
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.3 1 5.2
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
security_alert@emc.com 5.3 1.1 3.7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.