DSA-2023-343: Security Update for a Dell Precision Rack BIOS Vulnerability
Summary: Dell Precision Rack BIOS remediation is available for an improper privilege management vulnerability that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-32460 | Dell PowerEdge BIOS and Dell Precision BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. | 8.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-32460 | Dell PowerEdge BIOS and Dell Precision BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. | 8.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Affected Products & Remediation
| Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
BIOS Release Date |
Link |
|---|---|---|---|---|---|
| Precision 7910 Rack |
BIOS |
Versions prior to 2.18.0 |
Version 2.18.0 or later |
12/7/2023 |
|
| Precision 7910 XL Rack |
BIOS |
Versions prior to 2.18.0 |
Version 2.18.0 or later |
12/7/2023 |
|
| Precision 7920 Rack |
BIOS |
Versions prior to 2.20.1 |
Version 2.20.1 or later |
12/22/2023 |
|
| 7920 XL Rack |
BIOS |
Versions prior to 2.20.1 |
Version 2.20.1 or later |
12/22/2023 |
|
| Precision 7960 Rack |
BIOS |
Versions prior to 2.0.0 |
Version BIOS 2.0.0 or later |
01/23/2024 |
|
| Precision 7960 XL Rack |
BIOS |
Versions prior to 2.0.0 |
Version BIOS 2.0.0 or later |
01/23/2024 |
| Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
BIOS Release Date |
Link |
|---|---|---|---|---|---|
| Precision 7910 Rack |
BIOS |
Versions prior to 2.18.0 |
Version 2.18.0 or later |
12/7/2023 |
|
| Precision 7910 XL Rack |
BIOS |
Versions prior to 2.18.0 |
Version 2.18.0 or later |
12/7/2023 |
|
| Precision 7920 Rack |
BIOS |
Versions prior to 2.20.1 |
Version 2.20.1 or later |
12/22/2023 |
|
| 7920 XL Rack |
BIOS |
Versions prior to 2.20.1 |
Version 2.20.1 or later |
12/22/2023 |
|
| Precision 7960 Rack |
BIOS |
Versions prior to 2.0.0 |
Version BIOS 2.0.0 or later |
01/23/2024 |
|
| Precision 7960 XL Rack |
BIOS |
Versions prior to 2.0.0 |
Version BIOS 2.0.0 or later |
01/23/2024 |
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-12-07 | Initial Release |
| 2.0 | 2024-01-23 | Updated Affected Products and Remediation section: Final Platform list update |
| 3.0 | 2024-01-23 | Updated for enhanced presentation with no changes to content |