Debug Code Security Vulnerability in Dell PowerEdge and Precision BIOS
CVE-2023-44297

7.1HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
5 December 2023

Summary

A security flaw in Dell PowerEdge platforms and Precision BIOS versions exposes systems to risk. Unauthenticated physical attackers may exploit active debug code to gain unauthorized access, leading to potential information disclosure, tampering, or even code execution. The vulnerability highlights the importance of securing physical access to server hardware to prevent malicious actions.

Affected Version(s)

PowerEdge BIOS PowerEdge R660 Version 1.4.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.