CVE-2023-25537: High severity dell poweredge r740 firmware vulnerability
Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25537?
CVE-2023-25537 is considered a high-severity vulnerability due to its potential impact on system integrity.
How do I fix CVE-2023-25537?
To fix CVE-2023-25537, update the Dell PowerEdge 14G server BIOS to version 2.18.1 or higher.
Which Dell products are affected by CVE-2023-25537?
CVE-2023-25537 affects Dell PowerEdge 14G servers with BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2.
Can an attacker exploit CVE-2023-25537 remotely?
No, exploitation of CVE-2023-25537 requires local access by the attacker.
What type of vulnerability is CVE-2023-25537 classified as?
CVE-2023-25537 is classified as an Out of Bounds write vulnerability.