CVE-2023-44298

Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:poweredge_r660_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r660:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:poweredge_r760_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r760:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dell:poweredge_c6620_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_c6620:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dell:poweredge_mx760c_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_mx760c:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dell:poweredge_r860_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r860:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dell:poweredge_r960_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r960:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dell:poweredge_hs5610_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_hs5610:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dell:poweredge_hs5620_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_hs5620:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dell:poweredge_r660xs_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r660xs:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dell:poweredge_r760xs_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r760xs:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:dell:poweredge_r760xd2_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r760xd2:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:dell:poweredge_t560_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_t560:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:dell:poweredge_r760xa_firmware:1.4.4:*:*:*:*:*:*:*
cpe:2.3:h:dell:poweredge_r760xa:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-12-05 16:15

Updated : 2023-12-12 00:54


NVD link : CVE-2023-44298

Mitre link : CVE-2023-44298

CVE.ORG link : CVE-2023-44298


JSON object : View

Products Affected

dell

  • poweredge_hs5620
  • poweredge_r660
  • poweredge_r760_firmware
  • poweredge_c6620
  • poweredge_hs5610
  • poweredge_r960
  • poweredge_r960_firmware
  • poweredge_t560
  • poweredge_r860
  • poweredge_r660xs_firmware
  • poweredge_r860_firmware
  • poweredge_r660_firmware
  • poweredge_r760
  • poweredge_r760xs
  • poweredge_r760xd2
  • poweredge_r760xa
  • poweredge_c6620_firmware
  • poweredge_mx760c
  • poweredge_hs5610_firmware
  • poweredge_hs5620_firmware
  • poweredge_r760xa_firmware
  • poweredge_r760xd2_firmware
  • poweredge_t560_firmware
  • poweredge_r760xs_firmware
  • poweredge_r660xs
  • poweredge_mx760c_firmware
CWE
CWE-667

Improper Locking

CWE-1234

Hardware Internal or Debug Modes Allow Override of Locks