CWE
20 787
EPSS
0.043%
Advisory Published
Updated

CVE-2024-25942: Input Validation

First published: Tue Mar 19 2024(Updated: )

Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.

Credit: security_alert@emc.com

Affected SoftwareAffected VersionHow to fix
All of
Dell PowerEdge R730 Firmware<2.19.0
Dell PowerEdge R730 Firmware
All of
Dell PowerEdge R730xd Firmware<2.19.0
Dell PowerEdge R730xd Firmware
All of
Dell PowerEdge R630 Firmware<2.19.0
Dell PowerEdge R630
All of
Dell PowerEdge C4130<2.19.0
Dell PowerEdge C4130
All of
Dell PowerEdge r930 firmware<2.14.0
Dell PowerEdge R930
All of
Dell PowerEdge m630 (PE VRTX) Firmware<2.19.0
Dell PowerEdge M630p
All of
Dell PowerEdge m630 (PE VRTX) Firmware<2.19.0
Dell PowerEdge m630
All of
Dell PowerEdge FC630<2.19.0
Dell PowerEdge FC630
All of
Dell PowerEdge FC430<2.19.0
Dell PowerEdge FC430
All of
Dell PowerEdge m830 (pe vrtx) firmware<2.19.0
Dell M830
All of
Dell PowerEdge m830 (pe vrtx) firmware<2.19.0
Dell PowerEdge m830 (PE VRTX)
All of
Dell PowerEdge FC830<2.19.0
Dell PowerEdge FC830
All of
Dell PowerEdge t630 firmware<2.19.0
Dell PowerEdge T630
All of
Dell PowerEdge r530 firmware<2.19.0
Dell PowerEdge R530
All of
Dell PowerEdge R430 Firmware<2.19.0
Dell PowerEdge R430 Firmware
All of
Dell PowerEdge T430 Firmware<2.19.0
Dell PowerEdge T430 Firmware
All of
Dell PowerEdge R830<1.19.0
Dell PowerEdge R830
All of
Dell PowerEdge C6320 Firmware<2.19.0
Dell PowerEdge C6320
All of
Dell Storage Nx3230 Firmware<2.19.0
Dell NX3230 Firmware
All of
Dell NX3330<2.19.0
Dell NX3330 Firmware
All of
Dell XC6320<2.19.0
Dell XC6320 Firmware
All of
Dell XC430 Firmware<2.19.0
Dell XC430 Firmware
All of
Dell XC630 Firmware<2.19.0
Dell XC630 Firmware
All of
Dell XC730 Firmware<2.19.0
Dell XC730 Firmware
All of
Dell XC730xd Firmware<2.19.0
Dell XC730xd Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-25942?

    CVE-2024-25942 is considered a high severity vulnerability that allows a physical high privileged attacker to potentially exploit arbitrary writes to SMRAM.

  • How can I mitigate CVE-2024-25942?

    To mitigate CVE-2024-25942, update the affected Dell PowerEdge server BIOS to the latest version that addresses this vulnerability.

  • Which Dell PowerEdge server models are affected by CVE-2024-25942?

    CVE-2024-25942 affects various models including Dell PowerEdge R730, R630, R930, and several others listed in the advisory.

  • What type of attack is possible with CVE-2024-25942?

    CVE-2024-25942 allows for arbitrary writes to SMRAM, which could lead to potential unauthorized access or control over the system.

  • Is physical access required to exploit CVE-2024-25942?

    Yes, exploiting CVE-2024-25942 requires physical access to the vulnerable Dell PowerEdge server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203