VulnerabilityModified
CVE-2023-44297
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability.
MEDIUM 6.8EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1234, CWE-667
- Affected
- dell/poweredge r660 firmware · dell/poweredge r760 firmware · dell/poweredge c6620 firmware · dell/poweredge mx760c firmware · dell/poweredge r860 firmware · dell/poweredge r960 firmware · dell/poweredge hs5610 firmware · dell/poweredge hs5620 firmware · dell/poweredge r660xs firmware · dell/poweredge r760xs firmware · dell/poweredge r760xd2 firmware · dell/poweredge t560 firmware · dell/poweredge r760xa firmware
- Source
- security_alert@emc.com
References
- https://www.dell.com/support/kbdoc/en-us/000220047/dsa-2023-429-security-update-for-dell-16g-poweredge-server-bios-for-a-debug-code-security-vulnerabilityVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000220047/dsa-2023-429-security-update-for-dell-16g-poweredge-server-bios-for-a-debug-code-security-vulnerabilityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.