V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2020-5363
CVE
Medium

Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's mana…

CVSS
6.7
Medium
EPSS
0.00
p24
Published
2020-01-01
Updated
2020-01-01
Description

Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially allow an unauthorized actor, with physical access and/or OS administrator privileges to the device, to gain privileged access to the platform and the hard drive.

Tags · CWE
CWE-158
CAPEC-52
CAPEC-53
Affected products
Latitude_5300_2-in-1_firmwareLatitude_5300_firmwareLatitude_5400_firmwareLatitude_5401_firmwareLatitude_5500_firmwareLatitude_5501_firmwareLatitude_7200_2_in_1_firmwareLatitude_7220_firmwareLatitude_7220ex_rugged_extreme_tablet_firmwareLatitude_7300_firmwareLatitude_7400_firmwarePrecision_3540_firmwarePrecision_3541_firmwarePrecision_7540_firmwarePrecision_7740_firmwareXps_13_9300_firmwareXps_7390_2-in-1_firmwareXps_7590_firmware
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: H
High (H)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p24
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
latitude_5300_2-in-1_firmware*Tracked
latitude_5300_firmware*Tracked
latitude_5400_firmware*Tracked
latitude_5401_firmware*Tracked
latitude_5500_firmware*Tracked
latitude_5501_firmware*Tracked
latitude_7200_2_in_1_firmware*Tracked
latitude_7220_firmware*Tracked
latitude_7220ex_rugged_extreme_tablet_firmware*Tracked
latitude_7300_firmware*Tracked
latitude_7400_firmware*Tracked
precision_3540_firmware*Tracked
precision_3541_firmware*Tracked
precision_7540_firmware*Tracked
precision_7740_firmware*Tracked
xps_13_9300_firmware*Tracked
xps_7390_2-in-1_firmware*Tracked
xps_7590_firmware*Tracked
Source databases
CVE