Time-of-check Time-of-use (TOCTOU) Race Condition in PowerEdge Server BIOS and Precision Rack BIOS - CVE-2024-0163

 

Time-of-check Time-of-use (TOCTOU) Race Condition in PowerEdge Server BIOS and Precision Rack BIOS - CVE-2024-0163

Published: August 1, 2024


Vulnerability identifier: #VU95132
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0163
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to gain access to otherwise unauthorized resources.

The vulnerability exists due to TOCTOU race condition. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.


Affected software

PowerEdge Server BIOS
Precision Rack BIOS
PowerFlex Appliance
APEX Cloud Platform Foundation Software
APEX Cloud Platform for Red Hat OpenShift

How to mitigate CVE-2024-0163

Install updates from vendor's website.

PowerFlex Appliance - update to IC-46.380.01
APEX Cloud Platform Foundation Software - update to 03.00.04.01
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39

External References

Related Security Bulletins