Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| dell | poweredge_r740_firmware | 2.18.1 | - |
| dell | poweredge_r740xd_firmware | 2.18.1 | - |
| dell | poweredge_r640_firmware |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
30
Affected Products
2
References
dell / poweredge_r740_firmware
| 2.18.1 |
| - |
| dell | poweredge_r940_firmware | 2.18.1 | - |
| dell | poweredge_r540_firmware | 2.18.1 | - |
| dell | poweredge_r440_firmware | 2.18.1 | - |
| dell | poweredge_t440_firmware | 2.18.1 | - |
| dell | poweredge_xr2_firmware | 2.18.1 | - |
| dell | poweredge_r740xd2_firmware | 2.18.1 | - |
| dell | poweredge_r840_firmware | 2.18.1 | - |
| dell | poweredge_r940xa_firmware | 2.18.1 | - |
| dell | poweredge_t640_firmware | 2.18.1 | - |
| dell | poweredge_c6420_firmware | 2.18.1 | - |
| dell | poweredge_fc640_firmware | 2.18.1 | - |
| dell | poweredge_m640_firmware | 2.18.1 | - |
| dell | poweredge_mx740c_firmware | 2.18.1 | - |
| dell | poweredge_mx840c_firmware | 2.18.1 | - |
| dell | poweredge_c4140_firmware | 2.18.1 | - |
| dell | dss_8440_firmware | 2.18.1 | - |
| dell | poweredge_xe2420_firmware | 2.18.1 | - |
| dell | poweredge_xe7420_firmware | 2.18.1 | - |
| dell | poweredge_xe7440_firmware | 2.18.1 | - |
| dell | emc_storage_nx3240_firmware | 2.18.1 | - |
| dell | emc_storage_nx3340_firmware | 2.18.1 | - |
| dell | emc_xc_core_6420_firmware | 2.18.1 | - |
| dell | emc_xc_core_xc640_firmware | 2.18.1 | - |
| dell | emc_xc_core_xc740xd_firmware | 2.18.1 | - |
| dell | emc_xc_core_xc740xd2_firmware | 2.18.1 | - |
| dell | emc_xc_core_xc940_firmware | 2.18.1 | - |
| dell | emc_xc_core_xcxr2_firmware | 2.18.1 | - |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Exploitability
Impact