Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
21 Nov 2024, 08:45
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.dell.com/support/kbdoc/en-us/000226253/dsa-2024-039-security-update-for-dell-amd-based-poweredge-server-vulnerability - Vendor Advisory |
20 Aug 2024, 13:25
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:dell:poweredge_r7615:-:*:*:*:*:*:*:* cpe:2.3:h:dell:xc_core_xc7625:-:*:*:*:*:*:*:* cpe:2.3:o:dell:poweredge_r7625_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dell:poweredge_c6615:-:*:*:*:*:*:*:* cpe:2.3:h:dell:poweredge_r7625:-:*:*:*:*:*:*:* cpe:2.3:o:dell:poweredge_c6615_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dell:poweredge_r7615_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dell:poweredge_r6615_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dell:xc_core_xc7625_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dell:poweredge_r6625:-:*:*:*:*:*:*:* cpe:2.3:h:dell:poweredge_r6615:-:*:*:*:*:*:*:* cpe:2.3:o:dell:poweredge_r6625_firmware:*:*:*:*:*:*:*:* |
|
References | () https://www.dell.com/support/kbdoc/en-us/000226253/dsa-2024-039-security-update-for-dell-amd-based-poweredge-server-vulnerability - Vendor Advisory | |
Summary |
|
|
First Time |
Dell xc Core Xc7625
Dell poweredge R7615 Firmware Dell poweredge R6615 Dell xc Core Xc7625 Firmware Dell poweredge R7625 Dell poweredge R6625 Firmware Dell poweredge R7615 Dell Dell poweredge R7625 Firmware Dell poweredge R6615 Firmware Dell poweredge R6625 Dell poweredge C6615 Dell poweredge C6615 Firmware |
25 Jun 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-25 16:15
Updated : 2024-11-21 08:45
NVD link : CVE-2024-0171
Mitre link : CVE-2024-0171
CVE.ORG link : CVE-2024-0171
JSON object : View
Products Affected
dell
- poweredge_r7615_firmware
- poweredge_r6625_firmware
- poweredge_r7625_firmware
- poweredge_r6615_firmware
- poweredge_c6615
- xc_core_xc7625
- xc_core_xc7625_firmware
- poweredge_c6615_firmware
- poweredge_r6615
- poweredge_r7625
- poweredge_r6625
- poweredge_r7615
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition