Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially allow an unauthorized actor, with physical access and/or OS administrator privileges to the device, to gain privileged access to the platform and the hard drive.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Dell
Subscribe
|
Latitude 5300
Subscribe
Latitude 5300 2-in-1
Subscribe
Latitude 5300 2-in-1 Firmware
Subscribe
Latitude 5300 Firmware
Subscribe
Latitude 5400
Subscribe
Latitude 5400 Firmware
Subscribe
Latitude 5401
Subscribe
Latitude 5401 Firmware
Subscribe
Latitude 5500
Subscribe
Latitude 5500 Firmware
Subscribe
Latitude 5501
Subscribe
Latitude 5501 Firmware
Subscribe
Latitude 7200 2 In 1
Subscribe
Latitude 7200 2 In 1 Firmware
Subscribe
Latitude 7220
Subscribe
Latitude 7220 Firmware
Subscribe
Latitude 7220ex Rugged Extreme Tablet
Subscribe
Latitude 7220ex Rugged Extreme Tablet Firmware
Subscribe
Latitude 7300
Subscribe
Latitude 7300 Firmware
Subscribe
Latitude 7400
Subscribe
Latitude 7400 Firmware
Subscribe
Precision 3540
Subscribe
Precision 3540 Firmware
Subscribe
Precision 3541
Subscribe
Precision 3541 Firmware
Subscribe
Precision 7540
Subscribe
Precision 7540 Firmware
Subscribe
Precision 7740
Subscribe
Precision 7740 Firmware
Subscribe
Xps 13 9300
Subscribe
Xps 13 9300 Firmware
Subscribe
Xps 7390 2-in-1
Subscribe
Xps 7390 2-in-1 Firmware
Subscribe
Xps 7590
Subscribe
Xps 7590 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26545 | Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially allow an unauthorized actor, with physical access and/or OS administrator privileges to the device, to gain privileged access to the platform and the hard drive. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.dell.com/support/article/SLN321604 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T20:53:09.058Z
Reserved: 2020-01-03T00:00:00
Link: CVE-2020-5363
No data.
Status : Modified
Published: 2020-06-10T21:15:11.037
Modified: 2024-11-21T05:34:00.153
Link: CVE-2020-5363
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD