DSA-2024-200: Security Update for Dell PowerEdge T30 Mini Tower Server for an Improper Input Validation Vulnerability

Summary: Dell PowerEdge T30 Mini Tower Server remediation is available for an Improper Input Validation vulnerability that could be exploited by malicious users to compromise the affected systems. ...

Bu makale şunlar için geçerlidir: Bu makale şunlar için geçerli değildir: Bu makale, belirli bir ürüne bağlı değildir. Bu makalede tüm ürün sürümleri tanımlanmamıştır.

Impact

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-22429 Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution. 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-22429 Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution. 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Etkilenen Ürünler ve Düzeltme

Product Software/Firmware Affected Versions Remediated Versions Link
PowerEdge T30 BIOS Versions prior to 1.15.0  Version 1.15.0 or later  https://www.dell.com/support/home/product-support/product/poweredge-t30/drivers
Product Software/Firmware Affected Versions Remediated Versions Link
PowerEdge T30 BIOS Versions prior to 1.15.0  Version 1.15.0 or later  https://www.dell.com/support/home/product-support/product/poweredge-t30/drivers

Revision History

RevisionDateDescription
1.02024-05-22Initial release
2.02024-06-13updated for enhanced presentation with no changes to content

Acknowledgements

Dell would like to thank schur of BUPT, Dubhe Lab for reporting this issue.

Related Information

Etkilenen Ürünler

PowerEdge T30
Makale Özellikleri
Article Number: 000225022
Article Type: Dell Security Advisory
Son Değiştirme: 14 Haz 2024
Sorularınıza diğer Dell kullanıcılarından yanıtlar bulun
Destek Hizmetleri
Aygıtınızın Destek Hizmetleri kapsamında olup olmadığını kontrol edin.