7.9

CVE-2024-0172

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.

Data is provided by the National Vulnerability Database (NVD)
DellPoweredge R660 Firmware Version < 1.5.6
   DellPoweredge R660 Version-
DellPoweredge R760 Firmware Version < 1.5.6
   DellPoweredge R760 Version-
DellPoweredge C6620 Firmware Version < 1.5.6
   DellPoweredge C6620 Version-
DellPoweredge Mx760c Firmware Version < 1.5.6
   DellPoweredge Mx760c Version-
DellPoweredge R860 Firmware Version < 1.5.6
   DellPoweredge R860 Version-
DellPoweredge R960 Firmware Version < 1.5.6
   DellPoweredge R960 Version-
DellPoweredge Hs5610 Firmware Version < 1.5.6
   DellPoweredge Hs5610 Version-
DellPoweredge Hs5620 Firmware Version < 1.5.6
   DellPoweredge Hs5620 Version-
DellPoweredge R660xs Firmware Version < 1.5.6
   DellPoweredge R660xs Version-
DellPoweredge R760xs Firmware Version < 1.5.6
   DellPoweredge R760xs Version-
DellPoweredge R760xd2 Firmware Version < 1.5.6
   DellPoweredge R760xd2 Version-
DellPoweredge T560 Firmware Version < 1.5.6
   DellPoweredge T560 Version-
DellPoweredge R760xa Firmware Version < 1.1.3
   DellPoweredge R760xa Version-
DellPoweredge Xe9680 Firmware Version < 1.1.3
   DellPoweredge Xe9680 Version-
DellPoweredge Xr5610 Firmware Version < 1.1.4
   DellPoweredge Xr5610 Version-
DellPoweredge Xr8610t Firmware Version < 1.1.3
   DellPoweredge Xr8610t Version-
DellPoweredge Xr8620t Firmware Version < 1.1.3
   DellPoweredge Xr8620t Version-
DellPoweredge Xr7620 Firmware Version < 1.5.6
   DellPoweredge Xr7620 Version-
DellPoweredge Xe8640 Firmware Version < 1.2.5
   DellPoweredge Xe8640 Version-
DellPoweredge Xe9640 Firmware Version < 1.3.6
   DellPoweredge Xe9640 Version-
DellPoweredge R6615 Firmware Version < 1.4.6
   DellPoweredge R6615 Version-
DellPoweredge R7615 Firmware Version < 1.4.6
   DellPoweredge R7615 Version-
DellPoweredge R6625 Firmware Version < 1.4.6
   DellPoweredge R6625 Version-
DellPoweredge R7625 Firmware Version < 1.4.6
   DellPoweredge R7625 Version-
DellPoweredge R650 Firmware Version < 1.11.2
   DellPoweredge R650 Version-
DellPoweredge R750 Firmware Version < 1.11.2
   DellPoweredge R750 Version-
DellPoweredge R750xa Firmware Version < 1.11.2
   DellPoweredge R750xa Version-
DellPoweredge C6520 Firmware Version < 1.11.2
   DellPoweredge C6520 Version-
DellPoweredge Mx750c Firmware Version < 1.11.2
   DellPoweredge Mx750c Version-
DellPoweredge R550 Firmware Version < 1.11.2
   DellPoweredge R550 Version-
DellPoweredge R450 Firmware Version < 1.11.2
   DellPoweredge R450 Version-
DellPoweredge R650xs Firmware Version < 1.11.2
   DellPoweredge R650xs Version-
DellPoweredge R750xs Firmware Version < 1.11.2
   DellPoweredge R750xs Version-
DellPoweredge T550 Firmware Version < 1.11.2
   DellPoweredge T550 Version-
DellPoweredge Xr11 Firmware Version < 1.11.2
   DellPoweredge Xr11 Version-
DellPoweredge Xr12 Firmware Version < 1.11.2
   DellPoweredge Xr12 Version-
DellPoweredge T150 Firmware Version < 1.7.3
   DellPoweredge T150 Version-
DellPoweredge T350 Firmware Version < 1.7.3
   DellPoweredge T350 Version-
DellPoweredge R250 Firmware Version < 1.7.3
   DellPoweredge R250 Version-
DellPoweredge R350 Firmware Version < 1.7.3
   DellPoweredge R350 Version-
DellPoweredge Xr4510c Firmware Version < 1.12.1
   DellPoweredge Xr4510c Version-
DellPoweredge Xr4520c Firmware Version < 1.12.1
   DellPoweredge Xr4520c Version-
DellPoweredge R6515 Firmware Version < 2.12.4
   DellPoweredge R6515 Version-
DellPoweredge R6525 Firmware Version < 2.12.4
   DellPoweredge R6525 Version-
DellPoweredge R7515 Firmware Version < 2.12.4
   DellPoweredge R7515 Version-
DellPoweredge R7525 Firmware Version < 2.12.4
   DellPoweredge R7525 Version-
DellPoweredge C6525 Firmware Version < 2.12.4
   DellPoweredge C6525 Version-
DellPoweredge Xe8545 Firmware Version < 2.12.4
   DellPoweredge Xe8545 Version-
DellPoweredge R740 Firmware Version < 2.19.1
   DellPoweredge R740 Version-
DellPoweredge R740xd Firmware Version < 2.19.1
   DellPoweredge R740xd Version-
DellPoweredge R640 Firmware Version < 2.19.1
   DellPoweredge R640 Version-
DellPoweredge R940 Firmware Version < 2.19.1
   DellPoweredge R940 Version-
DellPoweredge R540 Firmware Version < 2.19.1
   DellPoweredge R540 Version-
DellPoweredge R440 Firmware Version < 2.19.1
   DellPoweredge R440 Version-
DellPoweredge T440 Firmware Version < 2.19.1
   DellPoweredge T440 Version-
DellPoweredge Xr2 Firmware Version < 2.19.1
   DellPoweredge Xr2 Version-
DellPoweredge R740xd2 Firmware Version < 2.19.1
   DellPoweredge R740xd2 Version-
DellPoweredge R840 Firmware Version < 2.19.1
   DellPoweredge R840 Version-
DellPoweredge R940xa Firmware Version < 2.19.1
   DellPoweredge R940xa Version-
DellPoweredge T640 Firmware Version < 2.19.1
   DellPoweredge T640 Version-
DellPoweredge C6420 Firmware Version < 2.19.1
   DellPoweredge C6420 Version-
DellPoweredge Fc640 Firmware Version < 2.19.1
   DellPoweredge Fc640 Version-
DellPoweredge M640 Firmware Version < 2.19.1
   DellPoweredge M640 Version-
DellPoweredge M640 (pe Vrtx) Firmware Version < 2.19.1
   DellPoweredge M640 (pe Vrtx) Version-
DellPoweredge Mx740c Firmware Version < 2.19.1
   DellPoweredge Mx740c Version-
DellPoweredge Mx840c Firmware Version < 2.19.1
   DellPoweredge Mx840c Version-
DellPoweredge C4140 Firmware Version < 2.19.1
   DellPoweredge C4140 Version-
DellDss 8440 Firmware Version < 2.19.0
   DellDss 8440 Version-
DellPoweredge Xe2420 Firmware Version < 2.19.0
   DellPoweredge Xe2420 Version-
DellPoweredge Xe7420 Firmware Version < 2.19.0
   DellPoweredge Xe7420 Version-
DellPoweredge Xe7440 Firmware Version < 2.19.0
   DellPoweredge Xe7440 Version-
DellPoweredge T140 Firmware Version < 2.14.1
   DellPoweredge T140 Version-
DellPoweredge T340 Firmware Version < 2.14.1
   DellPoweredge T340 Version-
DellPoweredge R240 Firmware Version < 2.14.1
   DellPoweredge R240 Version-
DellPoweredge R340 Firmware Version < 2.14.1
   DellPoweredge R340 Version-
DellPoweredge R6415 Firmware Version < 1.20.0
   DellPoweredge R6415 Version-
DellPoweredge R7415 Firmware Version < 1.20.0
   DellPoweredge R7415 Version-
DellPoweredge R7425 Firmware Version < 1.20.0
   DellPoweredge R7425 Version-
DellEmc Storage Nx3240 Firmware Version < 2.19.1
   DellEmc Storage Nx3240 Version-
DellEmc Storage Nx3340 Firmware Version < 2.19.1
   DellEmc Storage Nx3340 Version-
DellNx440 Firmware Version < 2.14.1
   DellNx440 Version-
DellEmc Xc Core Xc450 Firmware Version < 1.11.2
   DellEmc Xc Core Xc450 Version-
DellEmc Xc Core Xc650 Firmware Version < 1.11.2
   DellEmc Xc Core Xc650 Version-
DellEmc Xc Core Xc750 Firmware Version < 1.11.2
   DellEmc Xc Core Xc750 Version-
DellEmc Xc Core Xc750xa Firmware Version < 1.11.2
   DellEmc Xc Core Xc750xa Version-
DellEmc Xc Core Xc6520 Firmware Version < 1.11.2
   DellEmc Xc Core Xc6520 Version-
DellEmc Xc Core 6420 System Firmware Version < 2.19.1
   DellEmc Xc Core 6420 System Version-
DellEmc Xc Core Xc640 System Firmware Version < 2.19.1
   DellEmc Xc Core Xc640 System Version-
DellEmc Xc Core Xc740xd2 Firmware Version < 2.19.1
   DellEmc Xc Core Xc740xd2 Version-
DellEmc Xc Core Xc940 System Firmware Version < 2.19.1
   DellEmc Xc Core Xc940 System Version-
DellEmc Xc Core Xcxr2 Firmware Version < 2.19.1
   DellEmc Xc Core Xcxr2 Version-
DellEmc Xc Core Xc7525 Firmware Version < 2.12.4
   DellEmc Xc Core Xc7525 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.174
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security_alert@emc.com 7.9 2.5 4.7
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.