MEDIUM · 6.8

CVE-2019-3717

Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure B...

Vulnerability Description

Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DellChengming 3967 Firmware< 1.5.0
DellChengming 3967-
DellChengming 3977 Firmware< 1.6.0
DellChengming 3977-
DellChengming 3980 Firmware< 1.5.21
DellChengming 3980-
DellG3 3579 Firmware< 1.9.0
DellG3 3579-
DellG3 3779 Firmware< 1.9.0
DellG3 3779-
DellG5 5587 Firmware< 1.10.0
DellG5 5587-
DellG5 5590 Firmware< 1.3.1
DellG5 5590-
DellG7 7588 Firmware< 1.10.0
DellG7 7588-
DellG7 7590 Firmware< 1.3.1
DellG7 7590-
DellG7 7790 Firmware< 1.3.1
DellG7 7790-

References

FAQ

What is CVE-2019-3717?

CVE-2019-3717 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure B...

How severe is CVE-2019-3717?

CVE-2019-3717 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-3717?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Chengming 3967 Firmware, Dell Chengming 3967, Dell Chengming 3977 Firmware, Dell Chengming 3977, Dell Chengming 3980 Firmware.