Database/Firmware, BMC & network fabric
Dell iDRAC Service Module (out-of-bounds write): Out-of-bounds write allowing a privileged local attacker to execute
CVSS 5.8CVE-2024-38490Firmware, BMC & network fabriccurated
Impact
Out-of-bounds write allowing a privileged local attacker to execute code, typically ending in denial of service of the host.
Who can reach it
Privileged local user with interaction on the host.
What to do
Upgrade iSM past 5.3.0.0. Package update only.
References
Related entries
- EDK2: BIOS exposes sensitive information to a local unauthorized actorCVE-2024-38798 · TianoCore EDK2 (BIOS)Medium
- Arista EOS (PBR / BGP Flowspec / interface traffic policy): IPv4 packets carrying IP options can bypass policy-basedCVE-2024-6437 · Arista EOS (PBR / BGP Flowspec / interface traffic policy)Medium
- AMI AptioV UEFI BIOS: Improper input validation in the BIOS with an integrity impact and a changed scopeCVE-2025-33043 · AMI AptioV UEFI BIOSMedium
- Arista EOS (tunnel decapsulation): With VXLAN, decap-groups or GRE configured, the switch incorrectly decapsulates andCVE-2026-7473 · Arista EOS (tunnel decapsulation)Medium
- GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heapCVE-2020-15707 · GRUB2 (initrd size handling)Medium
- GRUB2 (PNG grayscale reader): Out-of-bounds write on the grayscale PNG pathCVE-2021-3696 · GRUB2 (PNG grayscale reader)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.