DSA-2023-384: Security Update for Dell Precision Rack Multiple Tianocore EDK2 Vulnerabilities
Summary: Dell Precision Rack remediation is available for multiple Tianocore EDK2 vulnerabilities that could be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
High
Additional Details
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Details
| Third-Party Component | CVE(s) | More information |
|---|---|---|
| Tianocore EDK2 | CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE-2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236, CVE-2023-45237 | See NVD (https://nvd.nist.gov/ |
Affected Products & Remediation
| Product | Software/Firmware | Affected Versions | Remediated Versions | BIOS Release Date | Link |
|---|---|---|---|---|---|
| Precision 7920 Rack | BIOS | Versions prior to 2.20.1 | Version 2.20.1 or later | 11/30/2023 | Go to the Drivers & Downloads site for updates. |
| 7920 XL Rack | BIOS | Versions prior to 2.20.1 | Version 2.20.1 or later | 11/30/2023 | Go to the Drivers & Downloads site for updates. |
| Precision 7910 Rack | BIOS | Versions prior to 2.18.0 | Version 2.18.0 or later | 12/6/2023 | Go to the Drivers & Downloads site for updates. |
| Precision 7910 XL Rack | BIOS | Versions prior to 2.18.0 | Version 2.18.0 or later | 12/6/2023 | Go to the Drivers & Downloads site for updates. |
| Precision 7960 Rack | BIOS | Versions prior to 2.0.0 | Version BIOS 2.0.0 or later | 01/23/2024 | Go to the Drivers & Downloads site for updates. |
| Precision 7960 XL Rack | BIOS | Versions prior to 2.0.0 | Version BIOS 2.0.0 or later | 01/23/2024 | Go to the Drivers & Downloads site for updates. |
| Product | Software/Firmware | Affected Versions | Remediated Versions | BIOS Release Date | Link |
|---|---|---|---|---|---|
| Precision 7920 Rack | BIOS | Versions prior to 2.20.1 | Version 2.20.1 or later | 11/30/2023 | Go to the Drivers & Downloads site for updates. |
| 7920 XL Rack | BIOS | Versions prior to 2.20.1 | Version 2.20.1 or later | 11/30/2023 | Go to the Drivers & Downloads site for updates. |
| Precision 7910 Rack | BIOS | Versions prior to 2.18.0 | Version 2.18.0 or later | 12/6/2023 | Go to the Drivers & Downloads site for updates. |
| Precision 7910 XL Rack | BIOS | Versions prior to 2.18.0 | Version 2.18.0 or later | 12/6/2023 | Go to the Drivers & Downloads site for updates. |
| Precision 7960 Rack | BIOS | Versions prior to 2.0.0 | Version BIOS 2.0.0 or later | 01/23/2024 | Go to the Drivers & Downloads site for updates. |
| Precision 7960 XL Rack | BIOS | Versions prior to 2.0.0 | Version BIOS 2.0.0 or later | 01/23/2024 | Go to the Drivers & Downloads site for updates. |
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-01-16 | Initial Release |
| 2.0 | 2024-01-23 | Updated Affected Products and Remediation section: Final Platform list update |
Related Information
Legal Disclaimer
Affected Products
R7910 XL, 7920 XL Rack, Precision 7960 XL Rack, Precision 7920 Rack, Precision Rack 7910, Precision 7960 RackArticle Properties
Article Number: 000218418
Article Type: Dell Security Advisory
Last Modified: 23 Jan 2024
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.