Skip to main content

DSA-2023-429: Security Update for Dell 16G PowerEdge Server BIOS for a Debug Code Security Vulnerability

Summary: Dell 16G PowerEdge Server BIOS remediation is available for a Debug Code Security Vulnerability that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-44297 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service. 7.1 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-44298 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service. 3.6 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-44297 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service. 7.1 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-44298 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service. 3.6 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Software/Firmware Affected Versions Remediated Versions Link
PowerEdge R660 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660/drivers
PowerEdge R760 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760/drivers
PowerEdge C6620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-c6620/drivers
PowerEdge MX760c BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-mx760c/drivers
PowerEdge R860 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r860/drivers
PowerEdge R960 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r960/drivers
PowerEdge HS5610 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5610/drivers
PowerEdge HS5620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5620/drivers
PowerEdge R660xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660xs/drivers
PowerEdge R760xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xs/drivers
PowerEdge R760xd2 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xd2/drivers
PowerEdge T560 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-t560/drivers
PowerEdge R760xa BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xa/drivers
Product Software/Firmware Affected Versions Remediated Versions Link
PowerEdge R660 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660/drivers
PowerEdge R760 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760/drivers
PowerEdge C6620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-c6620/drivers
PowerEdge MX760c BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-mx760c/drivers
PowerEdge R860 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r860/drivers
PowerEdge R960 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r960/drivers
PowerEdge HS5610 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5610/drivers
PowerEdge HS5620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5620/drivers
PowerEdge R660xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660xs/drivers
PowerEdge R760xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xs/drivers
PowerEdge R760xd2 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xd2/drivers
PowerEdge T560 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-t560/drivers
PowerEdge R760xa BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xa/drivers
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

Workarounds & Mitigations

None

Revision History

RevisionDateDescription
1.02023-12-04Initial release
2.02024-06-13Updated for enhanced presentation with no changes to content

Related Information

Affected Products

PowerEdge C6620, PowerEdge HS5610, PowerEdge HS5620, PowerEdge MX760c, PowerEdge R660, PowerEdge R660xs, PowerEdge R760, PowerEdge R760XA, PowerEdge R760xd2, PowerEdge R760xs, PowerEdge R860, PowerEdge R960, PowerEdge T560
Article Properties
Article Number: 000220047
Article Type: Dell Security Advisory
Last Modified: 13 Jun 2024
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.