HIGH · 7.1

CVE-2020-5362

Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS admi...

Vulnerability Description

Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.

CVSS Score

7.1

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
DellChengming 3967 Firmware< 1.9.0
DellChengming 3967-
DellChengming 3977 Firmware< 1.9.0
DellChengming 3977-
DellChengming 3980 Firmware< 2.16.0
DellChengming 3980-
DellChengming 3988 Firmware< 1.3.0
DellChengming 3988-
DellChengming 3990 Firmware< 1.1.3
DellChengming 3990-
DellChengming 3991 Firmware< 1.1.3
DellChengming 3991-
DellG3 15 3500 Firmware< 1.2.1
DellG3 15 3500-
DellG3 15 3590 Firmware< 1.11.0
DellG3 15 3590-
DellG3 3579 Firmware< 1.13.0
DellG3 3579-
DellG3 3779 Firmware< 1.13.0
DellG3 3779-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-5362?

CVE-2020-5362 is a vulnerability with a CVSS score of 7.1 (HIGH). Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS admi...

How severe is CVE-2020-5362?

CVE-2020-5362 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-5362?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Chengming 3967 Firmware, Dell Chengming 3967, Dell Chengming 3977 Firmware, Dell Chengming 3977, Dell Chengming 3980 Firmware.