CVE-2023-25537
Last modified
CVE-2023-25537 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege. . EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Poweredge R740 Firmware | < 2.18.1 |
| Dell | Poweredge R740xd Firmware | < 2.18.1 |
| Dell | Poweredge R640 Firmware | < 2.18.1 |
| Dell | Poweredge R940 Firmware | < 2.18.1 |
| Dell | Poweredge R540 Firmware | < 2.18.1 |
| Dell | Poweredge R440 Firmware | < 2.18.1 |
| Dell | Poweredge T440 Firmware | < 2.18.1 |
| Dell | Poweredge Xr2 Firmware | < 2.18.1 |
| Dell | Poweredge R740xd2 Firmware | < 2.18.1 |
| Dell | Poweredge R840 Firmware | < 2.18.1 |
| Dell | Poweredge R940xa Firmware | < 2.18.1 |
| Dell | Poweredge T640 Firmware | < 2.18.1 |
| Dell | Poweredge C6420 Firmware | < 2.18.1 |
| Dell | Poweredge Fc640 Firmware | < 2.18.1 |
| Dell | Poweredge M640 Firmware | < 2.18.1 |
| Dell | Poweredge Mx740c Firmware | < 2.18.1 |
| Dell | Poweredge Mx840c Firmware | < 2.18.1 |
| Dell | Poweredge C4140 Firmware | < 2.18.1 |
| Dell | Dss 8440 Firmware | < 2.18.1 |
| Dell | Poweredge Xe2420 Firmware | < 2.18.1 |
| Dell | Poweredge Xe7420 Firmware | < 2.18.1 |
| Dell | Poweredge Xe7440 Firmware | < 2.18.1 |
| Dell | Emc Storage Nx3240 Firmware | < 2.18.1 |
| Dell | Emc Storage Nx3340 Firmware | < 2.18.1 |
| Dell | Emc Xc Core 6420 Firmware | < 2.18.1 |
| Dell | Emc Xc Core Xc640 Firmware | < 2.18.1 |
| Dell | Emc Xc Core Xc740xd Firmware | < 2.18.1 |
| Dell | Emc Xc Core Xc740xd2 Firmware | < 2.18.1 |
| Dell | Emc Xc Core Xc940 Firmware | < 2.18.1 |
| Dell | Emc Xc Core Xcxr2 Firmware | < 2.18.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-25537?
How severe is CVE-2023-25537?
How do I fix CVE-2023-25537?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-25531NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where …9.8
- CVE-2023-25532NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where …7.5
- CVE-2023-25533NVIDIA DGX H100 BMC contains a vulnerability in the web UI, …9.8
- CVE-2023-25534NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where …9.8
- CVE-2023-25535 Dell SupportAssist for Home PCs Installer Executable file v…6.5
- CVE-2023-25536 Dell PowerScale OneFS 9.4.0.x contains exposure of sensitiv…6.7
- CVE-2023-25539 Dell NetWorker 19.6.1.2, contains an OS command injection V…9.8
- CVE-2023-2554External Control of File Name or Path in GitHub repository u…7.2
- CVE-2023-25540 Dell PowerScale OneFS 9.4.0.x contains an incorrect default…7.1
- CVE-2023-25542 Dell Trusted Device Agent, versions prior to 5.3.0, contain…7.8
- CVE-2023-25543 Dell Power Manager, versions prior to 3.14, contain an Impr…7.8
- CVE-2023-25544 Dell NetWorker versions 19.5 and earlier contain 'Apache To…6.5
Are you affected by CVE-2023-25537?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
