CVE-2023-25537
Summary
| CVE | CVE-2023-25537 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-22 11:15:00 UTC |
| Updated | 2023-05-30 21:32:00 UTC |
| Description | Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dell | Dss 8440 | - | All | All | All |
| Operating System | Dell | Dss 8440 Firmware | All | All | All | All |
| Hardware | Dell | Emc Storage Nx3240 | - | All | All | All |
| Operating System | Dell | Emc Storage Nx3240 Firmware | All | All | All | All |
| Hardware | Dell | Emc Storage Nx3340 | - | All | All | All |
| Operating System | Dell | Emc Storage Nx3340 Firmware | All | All | All | All |
| Hardware | Dell | Emc Xc Core 6420 | - | All | All | All |
| Operating System | Dell | Emc Xc Core 6420 Firmware | All | All | All | All |
| Hardware | Dell | Emc Xc Core Xc640 | - | All | All | All |
| Operating System | Dell | Emc Xc Core Xc640 Firmware | All | All | All | All |
| Hardware | Dell | Emc Xc Core Xc740xd | - | All | All | All |
| Hardware | Dell | Emc Xc Core Xc740xd2 | - | All | All | All |
| Operating System | Dell | Emc Xc Core Xc740xd2 Firmware | All | All | All | All |
| Operating System | Dell | Emc Xc Core Xc740xd Firmware | All | All | All | All |
| Hardware | Dell | Emc Xc Core Xc940 | - | All | All | All |
| Operating System | Dell | Emc Xc Core Xc940 Firmware | All | All | All | All |
| Hardware | Dell | Emc Xc Core Xcxr2 | - | All | All | All |
| Operating System | Dell | Emc Xc Core Xcxr2 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge C4140 | - | All | All | All |
| Operating System | Dell | Poweredge C4140 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge C6420 | - | All | All | All |
| Operating System | Dell | Poweredge C6420 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge Fc640 | - | All | All | All |
| Operating System | Dell | Poweredge Fc640 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge M640 | - | All | All | All |
| Operating System | Dell | Poweredge M640 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge Mx740c | - | All | All | All |
| Operating System | Dell | Poweredge Mx740c Firmware | All | All | All | All |
| Hardware | Dell | Poweredge Mx840c | - | All | All | All |
| Operating System | Dell | Poweredge Mx840c Firmware | All | All | All | All |
| Hardware | Dell | Poweredge R440 | - | All | All | All |
| Operating System | Dell | Poweredge R440 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge R540 | - | All | All | All |
| Operating System | Dell | Poweredge R540 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge R640 | - | All | All | All |
| Operating System | Dell | Poweredge R640 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge R740 | - | All | All | All |
| Hardware | Dell | Poweredge R740xd | - | All | All | All |
| Hardware | Dell | Poweredge R740xd2 | - | All | All | All |
| Operating System | Dell | Poweredge R740xd2 Firmware | All | All | All | All |
| Operating System | Dell | Poweredge R740xd Firmware | All | All | All | All |
| Operating System | Dell | Poweredge R740 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge R840 | - | All | All | All |
| Operating System | Dell | Poweredge R840 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge R940 | - | All | All | All |
| Hardware | Dell | Poweredge R940xa | - | All | All | All |
| Operating System | Dell | Poweredge R940xa Firmware | All | All | All | All |
| Operating System | Dell | Poweredge R940 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge T440 | - | All | All | All |
| Operating System | Dell | Poweredge T440 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge T640 | - | All | All | All |
| Operating System | Dell | Poweredge T640 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge Xe2420 | - | All | All | All |
| Operating System | Dell | Poweredge Xe2420 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge Xe7420 | - | All | All | All |
| Operating System | Dell | Poweredge Xe7420 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge Xe7440 | - | All | All | All |
| Operating System | Dell | Poweredge Xe7440 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge Xr2 | - | All | All | All |
| Operating System | Dell | Poweredge Xr2 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access Denied | MISC | www.dell.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.