DSA-2023-374: Security Update for Multiple Dell Precision Rack BIOS Vulnerabilities
Summary: Dell Precision Rack BIOS remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.
Acest articol se aplică pentru
Acest articol nu se aplică pentru
Acest articol nu este legat de un produs specific.
Acest articol nu acoperă toate versiunile de produs existente.
Impact
High
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-44297 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service. | 7.1 | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L |
| CVE-2023-44298 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service. | 3.6 | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-44297 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service. | 7.1 | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L |
| CVE-2023-44298 | Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service. | 3.6 | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L |
Produse afectate și măsuri de remediere
| Product | Software/Firmware | Affected Versions | Remediated Versions | BIOS Release Date | Link |
|---|---|---|---|---|---|
| Precision 7960 Rack | BIOS | Version 1.4.4 | Version 1.5.6 or later | 08/28/2023 | Go to the Drivers & Downloads site for updates. |
| Precision 7960 XL Rack | BIOS | Version 1.4.4 | Version 1.5.6 or later | 08/28/2023 | Go to the Drivers & Downloads site for updates. |
| Product | Software/Firmware | Affected Versions | Remediated Versions | BIOS Release Date | Link |
|---|---|---|---|---|---|
| Precision 7960 Rack | BIOS | Version 1.4.4 | Version 1.5.6 or later | 08/28/2023 | Go to the Drivers & Downloads site for updates. |
| Precision 7960 XL Rack | BIOS | Version 1.4.4 | Version 1.5.6 or later | 08/28/2023 | Go to the Drivers & Downloads site for updates. |
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-12-05 | Initial Release |
Related Information
Exonerare de răspundere
Produse afectate
Precision 7960 XL Rack, Precision 7960 RackProprietăți articol
Article Number: 000218135
Article Type: Dell Security Advisory
Ultima modificare: 05 Dec 2023
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.