SB2025052089 - Multiple vulnerabilities in Dell PowerEdge Server
Published: May 20, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2024-25571)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A local administrator can pass specially crafted input to the application and perform a denial of service (DoS) attack.
2) Sequence of processor instructions leads to unexpected behavior (CVE-ID: CVE-2024-37020)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an error related to processing of Sequence of processor instructions. A local user can cause a denial of service condition on the target system.
3) Buffer overflow (CVE-ID: CVE-2024-21859)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a boundary error in the UEFI firmware. A local administrator can trigger memory corruption and gain unauthorized access to sensitive information on the system.
4) Buffer overflow (CVE-ID: CVE-2024-31155)
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the UEFI firmware. A local administrator can trigger memory corruption and execute arbitrary code on the target system with elevated privileges.
5) Untrusted search path (CVE-ID: CVE-2024-24852)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path. A local user can execute arbitrary code with escalated privileges.
6) Out-of-bounds write (CVE-ID: CVE-2024-36274)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the Intel 800 Series Ethernet Driver. A remote attacker on the local network can trigger an out-of-bounds write and perform a denial of service (DoS) attack.
7) Incorrect Execution-Assigned Permissions (CVE-ID: CVE-2024-39286)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to incorrect execution-assigned permissions. A local user can gain unauthorized access to sensitive information on the system.
Remediation
Install update from vendor's website.