Missing Authentication for Critical Function in PowerEdge Server BIOS - CVE-2023-32460

 

Missing Authentication for Critical Function in PowerEdge Server BIOS - CVE-2023-32460

Published: June 14, 2024


Vulnerability identifier: #VU92125
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32460
CWE-ID: CWE-306
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions. A local user can trigger the vulnerability, bypass security restrictions and escalate privileges on the system.


Affected software

PowerEdge Server BIOS
PowerFlex Appliance
PowerFlex rack
Disk Library for mainframe (DLm)
Precision 7910 Rack
Precision 7910 XL Rack

How to mitigate CVE-2023-32460

Install update from vendor's website.

PowerFlex Appliance - update to IC 45.374.00
Precision 7910 Rack - update to 2.18.0
Precision 7910 XL Rack - update to 2.18.0
PowerFlex rack - addressed in versions 3.6.6.0, 3.7.4.0
Disk Library for mainframe (DLm) - update to 5.5.0.5

External References

Related Security Bulletins