CVE-2023-44297
Estado: ModificadaMedia (6.8)—
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 15
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (13)
Dell — Poweredge C6620 FirmwareDell — Poweredge Hs5610 FirmwareDell — Poweredge Hs5620 FirmwareDell — Poweredge Mx760c FirmwareDell — Poweredge R660 FirmwareDell — Poweredge R660xs FirmwareDell — Poweredge R760 FirmwareDell — Poweredge R760xa FirmwareDell — Poweredge R760xd2 FirmwareDell — Poweredge R760xs FirmwareDell — Poweredge R860 FirmwareDell — Poweredge R960 FirmwareDell — Poweredge T560 Firmware
CWE
- CWE-1234
- CWE-667
Referencias
- https://www.dell.com/support/kbdoc/en-us/000220047/dsa-2023-429-security-update-for-dell-16g-poweredge-server-bios-for-a-debug-code-security-vulnerability
- https://www.dell.com/support/kbdoc/en-us/000220047/dsa-2023-429-security-update-for-dell-16g-poweredge-server-bios-for-a-debug-code-security-vulnerability
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-44297",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security_alert@emc.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "PHYSICAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 0.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "Dell",
"product": "PowerEdge BIOS",
"versions": [
{
"status": "affected",
"version": "Version 1.4.4"
}
],
"platforms": [
"PowerEdge R660",
"PowerEdge R760",
"PowerEdge C6620",
"PowerEdge MX760c",
"PowerEdge R860",
"PowerEdge R960",
"PowerEdge HS5610",
"PowerEdge HS5620",
"PowerEdge R660xs",
"PowerEdge R760xs",
"PowerEdge R760xd2",
"PowerEdge T560",
"PowerEdge R760xa"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-12-05T16:15:07.097",
"references": [
{
"url": "https://www.dell.com/support/kbdoc/en-us/000220047/dsa-2023-429-security-update-for-dell-16g-poweredge-server-bios-for-a-debug-code-security-vulnerability",
"tags": [
"Vendor Advisory"
],
"source": "security_alert@emc.com"
},
{
"url": "https://www.dell.com/support/kbdoc/en-us/000220047/dsa-2023-429-security-update-for-dell-16g-poweredge-server-bios-for-a-debug-code-security-vulnerability",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security_alert@emc.com",
"description": [
{
"lang": "en",
"value": "CWE-1234"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-667"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "\nDell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service.\n\n"
},
{
"lang": "es",
"value": "Las plataformas Dell PowerEdge 16G Intel E5 BIOS y Dell Precision BIOS, versión 1.4.4, contienen una vulnerabilidad de seguridad de código de depuración activa. Un atacante físico no autenticado podría explotar esta vulnerabilidad, lo que provocaría la divulgación de información, la manipulación de información, la ejecución de código y la denegación de servicio."
}
],
"lastModified": "2026-06-17T06:27:19.113",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_r660_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9F11A33-BA61-4554-A0B2-8F789EA8BE3C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_r660:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "86AC134C-EFB7-46B8-B60F-5BD2663D7168"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_r760_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C301E8C7-01F7-4CBE-8666-74C0FD0BD58E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_r760:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "89E8485C-4298-4DA0-95AD-50C21BC2C798"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_c6620_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "18D7C139-E796-4361-9FE6-530D154D7062"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_c6620:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D360EB7D-5AB4-483C-BF00-53473B2D8AF4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_mx760c_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65443057-DC40-47A6-B739-E5984B7AEC43"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_mx760c:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2670A942-4200-46F2-A4FC-6D2F0E2074B9"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_r860_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1AC33C77-1C2C-4E44-A60F-14AE343666F8"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_r860:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B53D6488-A6E3-4505-8093-8232DC4219BD"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_r960_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9881FD7F-DA34-47F2-840B-929226E0D1CC"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_r960:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D5B42153-ED7B-433A-9070-9CAC972322BA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_hs5610_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B1E8504-EF8A-47D0-9762-5E944DD1ECDF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_hs5610:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "08A9C14A-7D1A-4724-BBBD-62FC4C66FCE1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_hs5620_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29F3D281-2810-4663-BD0F-F4EA67B1A321"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_hs5620:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "447BE381-9C9B-4339-B308-71D90DB60294"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_r660xs_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1E9ADAB6-42D2-44DE-8C0C-6DC4166DA705"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_r660xs:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "17FF7F29-F169-49B5-BEBA-6F20E3CDF1E6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_r760xs_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A99A3EEE-20D7-4E99-98FE-99012DA2393B"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_r760xs:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B3364A3E-BA9B-4588-89E5-A2C6C17B5D97"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_r760xd2_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5992CD2-83BA-4941-B3FF-42144036325E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_r760xd2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B21CBCD8-266A-4BCD-933D-2EF5F479B119"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_t560_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "033EB4DA-6B83-436C-AD42-63605EED7324"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_t560:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D4A86D53-1352-48FB-A26A-C898B2C6425E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:poweredge_r760xa_firmware:1.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3310CC98-2D26-42EF-8E10-13F2EB0D4FDB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dell:poweredge_r760xa:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "62603619-611F-4343-B75E-D45C50D1EA2F"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security_alert@emc.com"
}