SB2025052047 - Multiple vulnerabilities in Dell Networking Products



SB2025052047 - Multiple vulnerabilities in Dell Networking Products

Published: May 20, 2025

Security Bulletin ID SB2025052047
Severity
Low
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2023-28746)

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to information exposure through microarchitectural state after transient execution from some register files for some Intel Atom Processors. A local user can gain access to sensitive information.


2) Race condition (CVE-ID: CVE-2023-32282)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition in BIOS firmware. A local privileged user can exploit the race and escalate privileges on the system.


3) Security features bypass (CVE-ID: CVE-2023-22655)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a protection mechanism failure in some 3rd and 4th Generation Intel Xeon Processors when using Intel SGX or Intel TDX. A local user can execute arbitrary code with elevated privileges.


Remediation

Install update from vendor's website.