CVE-2024-0172

HIGH

Dell PowerEdge Server BIOS < 1.5.6 - Unauthenticated Privilege Escalation

Title source: llm
STIX 2.1

Description

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.

Scores

CVSS v3 7.9
EPSS 0.0006
EPSS Percentile 17.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (50)
dell/dss_8440_firmware < 2.19.0
dell/emc_storage_nx3240_firmware < 2.19.1
dell/emc_storage_nx3340_firmware < 2.19.1
dell/emc_xc_core_6420_system_firmware < 2.19.1
dell/emc_xc_core_xc450_firmware < 1.11.2
dell/emc_xc_core_xc640_system_firmware < 2.19.1
dell/emc_xc_core_xc650_firmware < 1.11.2
dell/emc_xc_core_xc6520_firmware < 1.11.2
dell/emc_xc_core_xc740xd2_firmware < 2.19.1
dell/emc_xc_core_xc740xd_system_firmware < 2.19.1
... and 40 more
Published Apr 03, 2024
Tracked Since Feb 18, 2026