DSA-2024-006: Security Update for Dell PowerEdge Server BIOS for an Improper SMM Communication Buffer Verification Vulnerability
Summary:
Dell PowerEdge Server BIOS remediation is available for an Improper SMM communication buffer verification vulnerability that could be exploited by malicious users to compromise the
affected system.
...
Please select a product to check article relevancy
This article applies to This article does not apply toThis article is not tied to any specific product.Not all product versions are identified in this article.
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Workarounds & Mitigations
None
Revision History
Revision
Date
Description
1.0
2024-03-12
Initial release
2.0
2024-03-13
Updated the CVE description to add "Dell Precision Rack BIOS"
Updated the downloadable links for PowerEdge XR4510c and PowerEdge XR4520c