Vulnerability Description
Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Latitude 7202 Firmware | < a28 |
| Dell | Latitude 7202 | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/article/SLN320792Vendor Advisory
- https://www.dell.com/support/article/SLN320792Vendor Advisory
FAQ
What is CVE-2020-5348?
CVE-2020-5348 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability ...
How severe is CVE-2020-5348?
CVE-2020-5348 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5348?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Latitude 7202 Firmware, Dell Latitude 7202.