Vulnerability Details CVE-2023-25537
Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.5%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2023-25537
-
cpe:2.3:h:dell:dss_8440:-
-
cpe:2.3:h:dell:emc_storage_nx3240:-
-
cpe:2.3:h:dell:emc_storage_nx3340:-
-
cpe:2.3:h:dell:emc_xc_core_6420:-
-
cpe:2.3:h:dell:emc_xc_core_xc640:-
-
cpe:2.3:h:dell:emc_xc_core_xc740xd2:-
-
cpe:2.3:h:dell:emc_xc_core_xc740xd:-
-
cpe:2.3:h:dell:emc_xc_core_xc940:-
-
cpe:2.3:h:dell:emc_xc_core_xcxr2:-
-
cpe:2.3:h:dell:poweredge_c4140:-
-
cpe:2.3:h:dell:poweredge_c6420:-
-
cpe:2.3:h:dell:poweredge_fc640:-
-
cpe:2.3:h:dell:poweredge_m640:-
-
cpe:2.3:h:dell:poweredge_mx740c:-
-
cpe:2.3:h:dell:poweredge_mx840c:-
-
cpe:2.3:h:dell:poweredge_r440:-
-
cpe:2.3:h:dell:poweredge_r540:-
-
cpe:2.3:h:dell:poweredge_r640:-
-
cpe:2.3:h:dell:poweredge_r740:-
-
cpe:2.3:h:dell:poweredge_r740xd2:-
-
cpe:2.3:h:dell:poweredge_r740xd:-
-
cpe:2.3:h:dell:poweredge_r840:-
-
cpe:2.3:h:dell:poweredge_r940:-
-
cpe:2.3:h:dell:poweredge_r940xa:-
-
cpe:2.3:h:dell:poweredge_t440:-
-
cpe:2.3:h:dell:poweredge_t640:-
-
cpe:2.3:h:dell:poweredge_xe2420:-
-
cpe:2.3:h:dell:poweredge_xe7420:-
-
cpe:2.3:h:dell:poweredge_xe7440:-
-
cpe:2.3:h:dell:poweredge_xr2:-
-
cpe:2.3:o:dell:dss_8440_firmware:-
-
cpe:2.3:o:dell:emc_storage_nx3240_firmware:-
-
cpe:2.3:o:dell:emc_storage_nx3340_firmware:-
-
cpe:2.3:o:dell:emc_xc_core_6420_firmware:-
-
cpe:2.3:o:dell:emc_xc_core_xc640_firmware:-
-
cpe:2.3:o:dell:emc_xc_core_xc740xd2_firmware:-
-
cpe:2.3:o:dell:emc_xc_core_xc740xd_firmware:-
-
cpe:2.3:o:dell:emc_xc_core_xc940_firmware:-
-
cpe:2.3:o:dell:emc_xc_core_xcxr2_firmware:-
-
cpe:2.3:o:dell:poweredge_c4140_firmware:-
-
cpe:2.3:o:dell:poweredge_c4140_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_c6420_firmware:-
-
cpe:2.3:o:dell:poweredge_c6420_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_fc640_firmware:-
-
cpe:2.3:o:dell:poweredge_fc640_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_m640_firmware:-
-
cpe:2.3:o:dell:poweredge_m640_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_mx740c_firmware:-
-
cpe:2.3:o:dell:poweredge_mx740c_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_mx740c_firmware:2.9.4
-
cpe:2.3:o:dell:poweredge_mx840c_firmware:-
-
cpe:2.3:o:dell:poweredge_mx840c_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_mx840c_firmware:2.9.4
-
cpe:2.3:o:dell:poweredge_r440_firmware:-
-
cpe:2.3:o:dell:poweredge_r440_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_r540_firmware:-
-
cpe:2.3:o:dell:poweredge_r540_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_r640_firmware:-
-
cpe:2.3:o:dell:poweredge_r640_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_r640_firmware:2.9.4
-
cpe:2.3:o:dell:poweredge_r740_firmware:-
-
cpe:2.3:o:dell:poweredge_r740_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_r740_firmware:2.9.4
-
cpe:2.3:o:dell:poweredge_r740xd2_firmware:-
-
cpe:2.3:o:dell:poweredge_r740xd2_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_r740xd_firmware:-
-
cpe:2.3:o:dell:poweredge_r740xd_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_r740xd_firmware:2.9.4
-
cpe:2.3:o:dell:poweredge_r840_firmware:-
-
cpe:2.3:o:dell:poweredge_r840_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_r840_firmware:2.9.4
-
cpe:2.3:o:dell:poweredge_r940_firmware:-
-
cpe:2.3:o:dell:poweredge_r940_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_r940_firmware:2.9.4
-
cpe:2.3:o:dell:poweredge_r940xa_firmware:-
-
cpe:2.3:o:dell:poweredge_r940xa_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_r940xa_firmware:2.9.4
-
cpe:2.3:o:dell:poweredge_t440_firmware:-
-
cpe:2.3:o:dell:poweredge_t440_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_t640_firmware:-
-
cpe:2.3:o:dell:poweredge_t640_firmware:2.11.2
-
cpe:2.3:o:dell:poweredge_xe2420_firmware:-
-
cpe:2.3:o:dell:poweredge_xe7420_firmware:-
-
cpe:2.3:o:dell:poweredge_xe7440_firmware:-
-
cpe:2.3:o:dell:poweredge_xr2_firmware:-
-
cpe:2.3:o:dell:poweredge_xr2_firmware:2.11.2