CVE Vulnerabilities

CVE-2024-0173

Access of Memory Location After End of Buffer

Published: Mar 13, 2024 | Modified: Jan 31, 2025
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.

Weakness

The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.

Affected Software

Name Vendor Start Version End Version
Poweredge_r660_firmware Dell * 2.0.0 (excluding)

References