CVE-2024-0154

LOW

Dell PowerEdge Server BIOS & Dell Precision Rack BIOS - Info Disclo...

Title source: llm

Description

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.

Scores

CVSS v3 3.8
EPSS 0.0009
EPSS Percentile 25.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Classification

CWE
CWE-125 CWE-788
Status published

Affected Products (50)

dell/poweredge_r660_firmware < 2.0.0
dell/poweredge_r760_firmware < 2.0.0
dell/poweredge_c6620_firmware < 2.0.0
dell/poweredge_mx760c_firmware < 2.0.0
dell/poweredge_r860_firmware < 1.8.0
dell/poweredge_r960_firmware < 1.8.0
dell/poweredge_hs5610_firmware < 2.0.0
dell/poweredge_hs5620_firmware < 2.0.0
dell/poweredge_r660xs_firmware < 2.0.0
dell/poweredge_r760xs_firmware < 2.0.0
dell/poweredge_r760xd2_firmware < 2.0.0
dell/poweredge_t560_firmware < 2.0.0
dell/poweredge_r760xa_firmware < 2.0.0
dell/poweredge_xe9680_firmware < 1.8.0
dell/poweredge_xr5610_firmware < 1.8.0
... and 35 more

Timeline

Published Mar 13, 2024
Tracked Since Feb 18, 2026