CVE-2023-32460

HIGH

Dell PowerEdge BIOS < 1.6.6 - Unauthenticated Privilege Escalation

Title source: llm
STIX 2.1

Description

Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 11.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (50)
dell/dss_8440_firmware < 2.20.0
dell/emc_nx440_firmware < 2.15.1
dell/emc_storage_nx3240_firmware < 2.20.1
dell/emc_storage_nx3340_firmware < 2.20.1
dell/emc_xc_core_6420_firmware < 2.20.1
dell/emc_xc_core_xc450_firmware < 1.12.1
dell/emc_xc_core_xc640_firmware < 2.20.1
dell/emc_xc_core_xc650_firmware < 1.12.1
dell/emc_xc_core_xc6520_firmware < 1.12.1
dell/emc_xc_core_xc740xd2_firmware < 2.20.1
... and 40 more
Published Dec 08, 2023
Tracked Since Feb 18, 2026