Impact
Dell Client Platform BIOS firmware contains a credential handling weakness (CWE‑305), allowing an attacker to bypass the primary authentication controls required for sensitive BIOS functions. If successful, the attacker can read protected data such as configuration settings, personal information, or other confidential information stored in the system. The vulnerability is only exploitable by an unauthenticated attacker who has physical access to the device, making it a local physical attack vector.
Affected Systems
Virtually all Dell client devices, including Latitude, Vostro, Alienware, Precision, OptiPlex, Pro, and many other laptop, ultrabook, all‑in‑one, and workstation models. All devices running BIOS firmware versions older than the latest update are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires physical proximity to the device; environments with weak physical security controls are therefore at higher risk. If access sensitive configuration and system data, potentially impacting confidentiality and trust in corporate assets.
OpenCVE Enrichment