CVE Feed

    Dashboard / CVE / CVE-2023-25537

    CVE-2023-25537

    Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.

    Published:May 22, 2023
    Last Modified:Jan 21, 2025
    EPS:May 22, 2023
    EPSS Score:0.00034
    CVSS Score:6.1

    Affected Products

    Vendor
    Dell
    Product
    Dss 8440
    Vendor
    Dell
    Product
    Dss 8440 Firmware
    Vendor
    Dell
    Product
    Emc Storage Nx3240
    Vendor
    Dell
    Product
    Emc Storage Nx3240 Firmware
    Vendor
    Dell
    Product
    Emc Storage Nx3340
    Vendor
    Dell
    Product
    Emc Storage Nx3340 Firmware
    Vendor
    Dell
    Product
    Emc Xc Core 6420
    Vendor
    Dell
    Product
    Emc Xc Core 6420 Firmware
    Vendor
    Dell
    Product
    Emc Xc Core Xc640
    Vendor
    Dell
    Product
    Emc Xc Core Xc640 Firmware
    Vendor
    Dell
    Product
    Emc Xc Core Xc740xd
    Vendor
    Dell
    Product
    Emc Xc Core Xc740xd2
    Vendor
    Dell
    Product
    Emc Xc Core Xc740xd2 Firmware
    Vendor
    Dell
    Product
    Emc Xc Core Xc740xd Firmware
    Vendor
    Dell
    Product
    Emc Xc Core Xc940
    Vendor
    Dell
    Product
    Emc Xc Core Xc940 Firmware
    Vendor
    Dell
    Product
    Emc Xc Core Xcxr2
    Vendor
    Dell
    Product
    Emc Xc Core Xcxr2 Firmware
    Vendor
    Dell
    Product
    Poweredge C4140
    Vendor
    Dell
    Product
    Poweredge C4140 Firmware
    Vendor
    Dell
    Product
    Poweredge C6420
    Vendor
    Dell
    Product
    Poweredge C6420 Firmware
    Vendor
    Dell
    Product
    Poweredge Fc640
    Vendor
    Dell
    Product
    Poweredge Fc640 Firmware
    Vendor
    Dell
    Product
    Poweredge M640
    Vendor
    Dell
    Product
    Poweredge M640 Firmware
    Vendor
    Dell
    Product
    Poweredge Mx740c
    Vendor
    Dell
    Product
    Poweredge Mx740c Firmware
    Vendor
    Dell
    Product
    Poweredge Mx840c
    Vendor
    Dell
    Product
    Poweredge Mx840c Firmware
    Vendor
    Dell
    Product
    Poweredge R440
    Vendor
    Dell
    Product
    Poweredge R440 Firmware
    Vendor
    Dell
    Product
    Poweredge R540
    Vendor
    Dell
    Product
    Poweredge R540 Firmware
    Vendor
    Dell
    Product
    Poweredge R640
    Vendor
    Dell
    Product
    Poweredge R640 Firmware
    Vendor
    Dell
    Product
    Poweredge R740
    Vendor
    Dell
    Product
    Poweredge R740 Firmware
    Vendor
    Dell
    Product
    Poweredge R740xd
    Vendor
    Dell
    Product
    Poweredge R740xd2
    Vendor
    Dell
    Product
    Poweredge R740xd2 Firmware
    Vendor
    Dell
    Product
    Poweredge R740xd Firmware
    Vendor
    Dell
    Product
    Poweredge R840
    Vendor
    Dell
    Product
    Poweredge R840 Firmware
    Vendor
    Dell
    Product
    Poweredge R940
    Vendor
    Dell
    Product
    Poweredge R940 Firmware
    Vendor
    Dell
    Product
    Poweredge R940xa
    Vendor
    Dell
    Product
    Poweredge R940xa Firmware
    Vendor
    Dell
    Product
    Poweredge T440
    Vendor
    Dell
    Product
    Poweredge T440 Firmware
    Vendor
    Dell
    Product
    Poweredge T640
    Vendor
    Dell
    Product
    Poweredge T640 Firmware
    Vendor
    Dell
    Product
    Poweredge Xe2420
    Vendor
    Dell
    Product
    Poweredge Xe2420 Firmware
    Vendor
    Dell
    Product
    Poweredge Xe7420
    Vendor
    Dell
    Product
    Poweredge Xe7420 Firmware
    Vendor
    Dell
    Product
    Poweredge Xe7440
    Vendor
    Dell
    Product
    Poweredge Xe7440 Firmware
    Vendor
    Dell
    Product
    Poweredge Xr2
    Vendor
    Dell
    Product
    Poweredge Xr2 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High