CVE-2024-25942

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/03/2024
Last modified:
04/02/2025

Description

Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:poweredge_r730_firmware:*:*:*:*:*:*:*:* 2.19.0 (excluding)
cpe:2.3:h:dell:poweredge_r730:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_r730xd_firmware:*:*:*:*:*:*:*:* 2.19.0 (excluding)
cpe:2.3:h:dell:poweredge_r730xd:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_r630_firmware:*:*:*:*:*:*:*:* 2.19.0 (excluding)
cpe:2.3:h:dell:poweredge_r630:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_c4130_firmware:*:*:*:*:*:*:*:* 2.19.0 (excluding)
cpe:2.3:h:dell:poweredge_c4130:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_r930_firmware:*:*:*:*:*:*:*:* 2.14.0 (excluding)
cpe:2.3:h:dell:poweredge_r930:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_m630_firmware:*:*:*:*:*:*:*:* 2.19.0 (excluding)
cpe:2.3:h:dell:poweredge_m630:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_m630_\(pe_vrtx\)_firmware:*:*:*:*:*:*:*:* 2.19.0 (excluding)
cpe:2.3:h:dell:poweredge_m630_\(pe_vrtx\):-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_fc630_firmware:*:*:*:*:*:*:*:* 2.19.0 (excluding)