Impact
set_attribute() writes the administrative password into the security area of a BIOS request buffer and then dumps the entire buffer, revealing the plaintext password in kernel logs. This creates a confidentiality flaw allowing an attacker who can capture the logs to obtain privileged credentials, classified as CWE-256.
Affected Systems
All Linux kernel installations that incorporate the Dell WMI System Manager module are affected. The vulnerability does not affect a specific kernel version in the input; any kernel version including this module is potentially vulnerable until the fix is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation yet. The likely attack vector requires local kernel access or the ability to read kernel logs, which may be possible through a local compromise or by exploiting privileged services that write to the system journal.
OpenCVE Enrichment