Dell PowerEdge Server BIOS Vulnerability: Arbitrary Writes to SMRAM
CVE-2024-25942
6.8MEDIUM
Summary
Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
Affected Version(s)
PowerEdge Platform < 2.19.0
PowerEdge Platform < 2.14.0
PowerEdge Platform < 1.19.0
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank schur of BUPT, Dubhe Lab for reporting this issue.