DSA-2024-037: Security Update for Dell Precision Rack BIOS for an Improper Input Validation Vulnerability
概要: Dell Precision Rack BIOS remediation is available for an Improper Input Validation vulnerability that could be exploited by malicious users to compromise the affected systems.
この記事は次に適用されます:
この記事は次には適用されません:
この記事は、特定の製品に関連付けられていません。
すべての製品パージョンがこの記事に記載されているわけではありません。
影響
High
詳細
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-0161 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM. | 7.5 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-0161 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM. | 7.5 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
影響を受ける製品と修復
| Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
BIOS Release Date |
Link |
|---|---|---|---|---|---|
| Precision 7920 Rack |
BIOS |
Versions 2.21.2 prior to |
Versions 2.21.2 or later |
03/12/2024 |
|
| 7920 XL Rack |
BIOS |
Versions 2.21.2 prior to |
Versions 2.21.2 or later |
03/12/2024 |
| Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
BIOS Release Date |
Link |
|---|---|---|---|---|---|
| Precision 7920 Rack |
BIOS |
Versions 2.21.2 prior to |
Versions 2.21.2 or later |
03/12/2024 |
|
| 7920 XL Rack |
BIOS |
Versions 2.21.2 prior to |
Versions 2.21.2 or later |
03/12/2024 |
変更履歴
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-03-13 | Initial Release |
関連情報
法的免責事項
対象製品
7920 XL Rack, Precision 7920 Rack文書のプロパティ
文書番号: 000222319
文書の種類: Dell Security Advisory
最終更新: 13 3月 2024
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。