Impact
Dell Client Platform BIOS firmware contains a credential handling weakness (CWE‑305) that allows an unauthenticated attacker with physical access to bypass primary authentication controls for BIOS functions. If the bypass succeeds, the attacker may read sensitive data stored in firmware or other system configuration areas, leading to confidential information disclosure. The flaw does not grant code execution; its primary impact is confidentiality compromise rather than integrity or availability disruption.
Affected Systems
Virtually all Dell client devices listed in the CNA products—including Latitude, Vostro, Alienware, Precision, OptiPlex, Pro, and numerous Ultrabook, All‑in‑One, and workstation models—are affected. The CVE does not specify firmware versions, so any device running a BIOS firmware containing the identified weakness is vulnerable, regardless of make or model within the Dell client portfolio.
Risk and Exploitability
The CVSS score of 5.3 marks moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation in the general population. The flaw is exploitable only by an attacker who can physically access the device; therefore, environments with weak physical security controls present higher risk. Even though the vulnerability is not listed in CISA’s KEV catalog, it remains relevant for organizations that rely on strong physical safeguards to protect firmware integrity.
OpenCVE Enrichment