Dell PowerEdge Server BIOS Vulnerability: Local Attacker Could Write to SMRAM
CVE-2024-0161

8.4HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
13 March 2024

Summary

Dell's PowerEdge Server BIOS and Precision Rack BIOS are susceptible to a vulnerability that arises from improper verification of the SMM communication buffer. This flaw permits a local attacker with low privileges to perform arbitrary write operations to the System Management RAM (SMRAM). Exploiting this vulnerability could lead to unauthorized modifications and potentially impact the stability and security of the system. Users of affected systems are encouraged to apply available security updates to mitigate the associated risks.

Affected Version(s)

PowerEdge Platform < 1.1.1

PowerEdge Platform < 1.13.2

PowerEdge Platform < 1.14.1

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank codebreaker1337 as well as schur of BUPT, Dubhe Lab for reporting this issue.
.