DSA-2023-451: Security Update for Dell Precision Rack BIOS for an Information Disclosure Vulnerability
Summary: Dell Precision Rack BIOS remediation is available for an Information Disclosure vulnerability that could be exploited by malicious users to compromise the affected systems.
Impact
Low
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-0173 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory. | 3.8 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-0173 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory. | 3.8 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Affected Products & Remediation
| Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
BIOS Release Date |
Link |
|---|---|---|---|---|---|
| Precision 7920 Rack |
BIOS |
Versions 2.21.2 prior to |
Versions 2.21.2 or later |
03/12/2024 |
|
| 7920 XL Rack |
BIOS |
Versions 2.21.2 prior to |
Versions 2.21.2 or later |
03/12/2024 |
|
| Precision 7960 Rack |
BIOS |
Versions prior to 2.0.0 |
Version 2.0.0 or later |
01/23/2024 |
|
| Precision 7960 XL Rack |
BIOS |
Versions prior to 2.0.0 |
Version 2.0.0 or later |
01/23/2024 |
| Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
BIOS Release Date |
Link |
|---|---|---|---|---|---|
| Precision 7920 Rack |
BIOS |
Versions 2.21.2 prior to |
Versions 2.21.2 or later |
03/12/2024 |
|
| 7920 XL Rack |
BIOS |
Versions 2.21.2 prior to |
Versions 2.21.2 or later |
03/12/2024 |
|
| Precision 7960 Rack |
BIOS |
Versions prior to 2.0.0 |
Version 2.0.0 or later |
01/23/2024 |
|
| Precision 7960 XL Rack |
BIOS |
Versions prior to 2.0.0 |
Version 2.0.0 or later |
01/23/2024 |
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-03-13 | Initial Release |