Dell PowerEdge Server BIOS Vulnerability: Local Attacker Could Write to SMRAM
CVE-2024-0161
8.4HIGH
Summary
Dell's PowerEdge Server BIOS and Precision Rack BIOS are susceptible to a vulnerability that arises from improper verification of the SMM communication buffer. This flaw permits a local attacker with low privileges to perform arbitrary write operations to the System Management RAM (SMRAM). Exploiting this vulnerability could lead to unauthorized modifications and potentially impact the stability and security of the system. Users of affected systems are encouraged to apply available security updates to mitigate the associated risks.
Affected Version(s)
PowerEdge Platform < 1.1.1
PowerEdge Platform < 1.13.2
PowerEdge Platform < 1.14.1
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank codebreaker1337 as well as schur of BUPT, Dubhe Lab for reporting this issue.