DSA-2023-374: Security Update for Multiple Dell Precision Rack BIOS Vulnerabilities
Summary: Dell Precision Rack BIOS remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
High
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-44297 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service. | 7.1 | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L |
| CVE-2023-44298 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service. | 3.6 | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-44297 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service. | 7.1 | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L |
| CVE-2023-44298 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service. | 3.6 | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L |
Affected Products & Remediation
| Product | Software/Firmware | Affected Versions | Remediated Versions | BIOS Release Date | Link |
|---|---|---|---|---|---|
| Precision 7960 Rack | BIOS | Version 1.4.4 | Version 1.5.6 or later | 08/28/2023 | Go to the Drivers & Downloads site for updates. |
| Precision 7960 XL Rack | BIOS | Version 1.4.4 | Version 1.5.6 or later | 08/28/2023 | Go to the Drivers & Downloads site for updates. |
| Product | Software/Firmware | Affected Versions | Remediated Versions | BIOS Release Date | Link |
|---|---|---|---|---|---|
| Precision 7960 Rack | BIOS | Version 1.4.4 | Version 1.5.6 or later | 08/28/2023 | Go to the Drivers & Downloads site for updates. |
| Precision 7960 XL Rack | BIOS | Version 1.4.4 | Version 1.5.6 or later | 08/28/2023 | Go to the Drivers & Downloads site for updates. |
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-12-05 | Initial Release |
Related Information
Legal Disclaimer
Affected Products
Precision 7960 XL Rack, Precision 7960 RackArticle Properties
Article Number: 000218135
Article Type: Dell Security Advisory
Last Modified: 05 Dec 2023
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.