CVE-2024-25948

Aug. 1, 2024, 12:42 p.m.

Undergoing Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Dell iDRAC Service Module

  • 5.3.0.0 and prior

Source

security_alert@emc.com

Tags

CVE-2024-25948 details

Published : Aug. 1, 2024, 8:15 a.m.
Last Modified : Aug. 1, 2024, 12:42 p.m.

Description

Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.

CVSS Score

1 2 3 4.8 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-787 Out-of-bounds Write The product writes data past the end, or before the beginning, of the intended buffer.

CVSS Data

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

Base Score

4.8

Exploitability Score

0.6

Impact Score

4.2

Base Severity

MEDIUM

This website uses the NVD API, but is not approved or certified by it.