Database/Firmware, BMC & network fabric
Dell PowerEdge Server BIOS (heap-based buffer overflow): A high-privileged local attacker writes to memory it should
CVSS 7.2CVE-2024-22453Firmware, BMC & network fabriccurated
Impact
A high-privileged local attacker writes to memory it should not reach, with scope change - firmware-level memory corruption on the server platform.
Who can reach it
Local high-privilege access to the host.
What to do
Flash the fixed PowerEdge BIOS. A BIOS update is a cold reboot per node and cannot be done live - on a GPU fleet that means draining jobs and taking the box out of the scheduler, so batch it with other firmware work rather than doing a standalone pass.
References
Related entries
- Lenovo XClarity Controller (XCC) - IPMI command handler: A specially crafted IPMI command gives an authenticated XCCCVE-2024-38509 · Lenovo XClarity Controller (XCC) - IPMI command handlerHigh
- AMI AptioV UEFI BIOS (SMM): A memory-bounds bug in the BIOS that lets an attacker execute code outside the intendedCVE-2024-42442 · AMI AptioV UEFI BIOS (SMM)High
- AMD Zen microcode patch loader (CPU ROM signature verification): The CPU ROM's microcode patch loader verified patchCVE-2024-56161 · AMD Zen microcode patch loader (CPU ROM signature verification)High
- AMD CPU microcode patch loading - improper cleanup: Improper cleanup during microcode patch loading gives a localCVE-2025-0032 · AMD CPU microcode patch loading - improper cleanupHigh
- Supermicro BMC firmware validation logic on the X12STW-F motherboard: An attacker with administrative reach to the BMCCVE-2025-12006 · Supermicro BMC firmware validation logic on the X12STW-F motherboardHigh
- Intel CSME firmware (TOCTOU): A time-of-check/time-of-use race in CSME firmware lets a privileged local user escalateCVE-2025-20037 · Intel CSME firmware (TOCTOU)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.