CVE-2024-0172
Last modified
CVE-2024-0172 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Poweredge R660 Firmware | < 1.5.6 |
| Dell | Poweredge R760 Firmware | < 1.5.6 |
| Dell | Poweredge C6620 Firmware | < 1.5.6 |
| Dell | Poweredge Mx760c Firmware | < 1.5.6 |
| Dell | Poweredge R860 Firmware | < 1.5.6 |
| Dell | Poweredge R960 Firmware | < 1.5.6 |
| Dell | Poweredge Hs5610 Firmware | < 1.5.6 |
| Dell | Poweredge Hs5620 Firmware | < 1.5.6 |
| Dell | Poweredge R660xs Firmware | < 1.5.6 |
| Dell | Poweredge R760xs Firmware | < 1.5.6 |
| Dell | Poweredge R760xd2 Firmware | < 1.5.6 |
| Dell | Poweredge T560 Firmware | < 1.5.6 |
| Dell | Poweredge R760xa Firmware | < 1.1.3 |
| Dell | Poweredge Xe9680 Firmware | < 1.1.3 |
| Dell | Poweredge Xr5610 Firmware | < 1.1.4 |
| Dell | Poweredge Xr8610t Firmware | < 1.1.3 |
| Dell | Poweredge Xr8620t Firmware | < 1.1.3 |
| Dell | Poweredge Xr7620 Firmware | < 1.5.6 |
| Dell | Poweredge Xe8640 Firmware | < 1.2.5 |
| Dell | Poweredge Xe9640 Firmware | < 1.3.6 |
| Dell | Poweredge R6615 Firmware | < 1.4.6 |
| Dell | Poweredge R7615 Firmware | < 1.4.6 |
| Dell | Poweredge R6625 Firmware | < 1.4.6 |
| Dell | Poweredge R7625 Firmware | < 1.4.6 |
| Dell | Poweredge R650 Firmware | < 1.11.2 |
| Dell | Poweredge R750 Firmware | < 1.11.2 |
| Dell | Poweredge R750xa Firmware | < 1.11.2 |
| Dell | Poweredge C6520 Firmware | < 1.11.2 |
| Dell | Poweredge Mx750c Firmware | < 1.11.2 |
| Dell | Poweredge R550 Firmware | < 1.11.2 |
| Dell | Poweredge R450 Firmware | < 1.11.2 |
| Dell | Poweredge R650xs Firmware | < 1.11.2 |
| Dell | Poweredge R750xs Firmware | < 1.11.2 |
| Dell | Poweredge T550 Firmware | < 1.11.2 |
| Dell | Poweredge Xr11 Firmware | < 1.11.2 |
| Dell | Poweredge Xr12 Firmware | < 1.11.2 |
| Dell | Poweredge T150 Firmware | < 1.7.3 |
| Dell | Poweredge T350 Firmware | < 1.7.3 |
| Dell | Poweredge R250 Firmware | < 1.7.3 |
| Dell | Poweredge R350 Firmware | < 1.7.3 |
| Dell | Poweredge Xr4510c Firmware | < 1.12.1 |
| Dell | Poweredge Xr4520c Firmware | < 1.12.1 |
| Dell | Poweredge R6515 Firmware | < 2.12.4 |
| Dell | Poweredge R6525 Firmware | < 2.12.4 |
| Dell | Poweredge R7515 Firmware | < 2.12.4 |
| Dell | Poweredge R7525 Firmware | < 2.12.4 |
| Dell | Poweredge C6525 Firmware | < 2.12.4 |
| Dell | Poweredge Xe8545 Firmware | < 2.12.4 |
| Dell | Poweredge R740 Firmware | < 2.19.1 |
| Dell | Poweredge R740xd Firmware | < 2.19.1 |
Showing 50 of 93 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-0172?
How severe is CVE-2024-0172?
How do I fix CVE-2024-0172?
Are you affected by CVE-2024-0172?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
