Database/Firmware, BMC & network fabric
Dell PowerEdge Server BIOS / Precision Rack BIOS (improper privilege management): An unauthenticated local attacker
CVSS 7.9CVE-2024-0172Firmware, BMC & network fabriccurated
Impact
An unauthenticated local attacker escalates privilege with scope change - a firmware-level escalation that survives OS reinstall and is invisible to host-based tooling.
Who can reach it
Local access to the server. On bare-metal GPU rental this is the tenant themselves.
What to do
Flash the fixed PowerEdge BIOS. A BIOS update is a cold reboot per node and cannot be done live - on a GPU fleet that means draining jobs and taking the box out of the scheduler, so batch it with other firmware work rather than doing a standalone pass.
References
Related entries
- AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena): SNP firmware fails to restrict where a hypervisor-drivenCVE-2024-21980 · AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena)High
- Intel reference platforms (Seamless Firmware Updates): A race condition in the seamless firmware update mechanism letsCVE-2024-23599 · Intel reference platforms (Seamless Firmware Updates)High
- Dell SmartFabric OS10 (hard-coded password): A hard-coded password in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-39585 · Dell SmartFabric OS10 (hard-coded password)High
- Insyde InsydeH2O (VariableRuntimeDxe, SecureBootHandler): The Secure Boot variable handler bounds-checks incoming dataCVE-2024-52880 · Insyde InsydeH2O (VariableRuntimeDxe, SecureBootHandler)High
- Intel Xeon 6 with TDX (protected memory range handling): Improper handling of overlap between protected memory rangesCVE-2025-22889 · Intel Xeon 6 with TDX (protected memory range handling)High
- IBM Power Systems Firmware: BMC/FSP root can read and disrupt host processor state across all partitionsCVE-2026-17063 · IBM Power Systems Firmware (BMC/FSP-to-host interface, processor state)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.