Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000220047


DSA-2023-429: Security Update for Dell 16G PowerEdge Server BIOS for a Debug Code Security Vulnerability

Summary: Dell 16G PowerEdge Server BIOS remediation is available for a Debug Code Security Vulnerability that could be exploited by malicious users to compromise the affected system.

Article Content


Impact

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-44297 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service. 7.1 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-44298 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service. 3.6 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-44297 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service. 7.1 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-44298 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service. 3.6 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Software/Firmware Affected Versions Remediated Versions Link
PowerEdge R660 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660/drivers
PowerEdge R760 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760/drivers
PowerEdge C6620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-c6620/drivers
PowerEdge MX760c BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-mx760c/drivers
PowerEdge R860 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r860/drivers
PowerEdge R960 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r960/drivers
PowerEdge HS5610 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5610/drivers
PowerEdge HS5620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5620/drivers
PowerEdge R660xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660xs/drivers
PowerEdge R760xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xs/drivers
PowerEdge R760xd2 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xd2/drivers
PowerEdge T560 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-t560/drivers
PowerEdge R760xa BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xa/drivers
Product Software/Firmware Affected Versions Remediated Versions Link
PowerEdge R660 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660/drivers
PowerEdge R760 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760/drivers
PowerEdge C6620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-c6620/drivers
PowerEdge MX760c BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-mx760c/drivers
PowerEdge R860 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r860/drivers
PowerEdge R960 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r960/drivers
PowerEdge HS5610 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5610/drivers
PowerEdge HS5620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5620/drivers
PowerEdge R660xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660xs/drivers
PowerEdge R760xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xs/drivers
PowerEdge R760xd2 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xd2/drivers
PowerEdge T560 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-t560/drivers
PowerEdge R760xa BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xa/drivers
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

Workarounds and Mitigations

None

Revision History

RevisionDateDescription
1.02023-12-04Initial release
2.02024-06-13Updated for enhanced presentation with no changes to content

Related Information


Article Properties


Affected Product

PowerEdge C6620, PowerEdge HS5610, PowerEdge HS5620, PowerEdge MX760c, PowerEdge R660, PowerEdge R660xs, PowerEdge R760, PowerEdge R760XA, PowerEdge R760xd2, PowerEdge R760xs, PowerEdge R860, PowerEdge R960, PowerEdge T560

Last Published Date

13 Jun 2024

Article Type

Dell Security Advisory