CVE-2024-25942: Input Validation

Published Mar 19, 2024
·
Updated

Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.

Affected Software

50 affected components
All of the following
Dell Poweredge R730 Firmware<2.19.0
Dell Poweredge R730
All of the following
Dell Poweredge R730xd Firmware<2.19.0
Dell Poweredge R730xd
All of the following
Dell Poweredge R630 Firmware<2.19.0
Dell Poweredge R630
All of the following
Dell Poweredge C4130 Firmware<2.19.0
Dell Poweredge C4130
All of the following
Dell Poweredge R930 Firmware<2.14.0
Dell Poweredge R930
All of the following
Dell Poweredge M630 Firmware<2.19.0
Dell Poweredge M630
All of the following
Dell Poweredge M630 \(pe Vrtx\) Firmware<2.19.0
Dell Poweredge M630 \(pe Vrtx\)
All of the following
Dell Poweredge Fc630 Firmware<2.19.0
Dell Poweredge Fc630
All of the following
Dell Poweredge Fc430 Firmware<2.19.0
Dell Poweredge Fc430
All of the following
Dell Poweredge M830 Firmware<2.19.0
Dell Poweredge M830
All of the following
Dell Poweredge M830 \(pe Vrtx\) Firmware<2.19.0
Dell Poweredge M830 \(pe Vrtx\)
All of the following
Dell Poweredge Fc830 Firmware<2.19.0
Dell Poweredge Fc830
All of the following
Dell Poweredge T630 Firmware<2.19.0
Dell Poweredge T630
All of the following
Dell Poweredge R530 Firmware<2.19.0
Dell Poweredge R530
All of the following
Dell Poweredge R430 Firmware<2.19.0
Dell Poweredge R430
All of the following
Dell Poweredge T430 Firmware<2.19.0
Dell Poweredge T430
All of the following
Dell Poweredge R830 Firmware<1.19.0
Dell Poweredge R830
All of the following
Dell Poweredge C6320 Firmware<2.19.0
Dell Poweredge C6320
All of the following
Dell Nx3230 Firmware<2.19.0
Dell Nx3230
All of the following
Dell Nx3330 Firmware<2.19.0
Dell Nx3330
All of the following
Dell Xc6320 Firmware<2.19.0
Dell Xc6320
All of the following
Dell Xc430 Firmware<2.19.0
Dell Xc430
All of the following
Dell Xc630 Firmware<2.19.0
Dell Xc630
All of the following
Dell Xc730 Firmware<2.19.0
Dell Xc730
All of the following
Dell Xc730xd Firmware<2.19.0
Dell Xc730xd

Event History

Mar 19, 2024
CVE Published
via MITRE·07:52 AM
Data Sourced
via MITRE·07:52 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-25942?

CVE-2024-25942 is considered a high severity vulnerability that allows a physical high privileged attacker to potentially exploit arbitrary writes to SMRAM.

2

How can I mitigate CVE-2024-25942?

To mitigate CVE-2024-25942, update the affected Dell PowerEdge server BIOS to the latest version that addresses this vulnerability.

3

Which Dell PowerEdge server models are affected by CVE-2024-25942?

CVE-2024-25942 affects various models including Dell PowerEdge R730, R630, R930, and several others listed in the advisory.

4

What type of attack is possible with CVE-2024-25942?

CVE-2024-25942 allows for arbitrary writes to SMRAM, which could lead to potential unauthorized access or control over the system.

5

Is physical access required to exploit CVE-2024-25942?

Yes, exploiting CVE-2024-25942 requires physical access to the vulnerable Dell PowerEdge server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203