Description
Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially allow an unauthorized actor, with physical access and/or OS administrator privileges to the device, to gain privileged access to the platform and the hard drive.
Published: 2020-06-10
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-26545 Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially allow an unauthorized actor, with physical access and/or OS administrator privileges to the device, to gain privileged access to the platform and the hard drive.
History

No history.

Subscriptions

Dell Latitude 5300 Latitude 5300 2-in-1 Latitude 5300 2-in-1 Firmware Latitude 5300 Firmware Latitude 5400 Latitude 5400 Firmware Latitude 5401 Latitude 5401 Firmware Latitude 5500 Latitude 5500 Firmware Latitude 5501 Latitude 5501 Firmware Latitude 7200 2 In 1 Latitude 7200 2 In 1 Firmware Latitude 7220 Latitude 7220 Firmware Latitude 7220ex Rugged Extreme Tablet Latitude 7220ex Rugged Extreme Tablet Firmware Latitude 7300 Latitude 7300 Firmware Latitude 7400 Latitude 7400 Firmware Precision 3540 Precision 3540 Firmware Precision 3541 Precision 3541 Firmware Precision 7540 Precision 7540 Firmware Precision 7740 Precision 7740 Firmware Xps 13 9300 Xps 13 9300 Firmware Xps 7390 2-in-1 Xps 7390 2-in-1 Firmware Xps 7590 Xps 7590 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-16T20:53:09.058Z

Reserved: 2020-01-03T00:00:00.000Z

Link: CVE-2020-5363

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-10T21:15:11.037

Modified: 2024-11-21T05:34:00.153

Link: CVE-2020-5363

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses