Vulnerability Description
Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially allow an unauthorized actor, with physical access and/or OS administrator privileges to the device, to gain privileged access to the platform and the hard drive.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Latitude 5300 Firmware | < 1.9.4 |
| Dell | Latitude 5300 | - |
| Dell | Latitude 5300 2-In-1 Firmware | < 1.9.4 |
| Dell | Latitude 5300 2-In-1 | - |
| Dell | Latitude 5400 Firmware | < 1.7.4 |
| Dell | Latitude 5400 | - |
| Dell | Latitude 5401 Firmware | < 1.8.4 |
| Dell | Latitude 5401 | - |
| Dell | Latitude 5500 Firmware | < 1.7.4 |
| Dell | Latitude 5500 | - |
| Dell | Latitude 5501 Firmware | < 1.8.4 |
| Dell | Latitude 5501 | - |
| Dell | Latitude 7200 2 In 1 Firmware | < 1.8.0 |
| Dell | Latitude 7200 2 In 1 | - |
| Dell | Latitude 7220 Firmware | < 1.6.0 |
| Dell | Latitude 7220 | - |
| Dell | Latitude 7220Ex Rugged Extreme Tablet Firmware | < 1.6.0 |
| Dell | Latitude 7220Ex Rugged Extreme Tablet | - |
| Dell | Latitude 7300 Firmware | < 1.7.4 |
| Dell | Latitude 7300 | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/article/SLN321604Vendor Advisory
- https://www.dell.com/support/article/SLN321604Vendor Advisory
FAQ
What is CVE-2020-5363?
CVE-2020-5363 is a vulnerability with a CVSS score of 8.6 (HIGH). Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Adm...
How severe is CVE-2020-5363?
CVE-2020-5363 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5363?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Latitude 5300 Firmware, Dell Latitude 5300, Dell Latitude 5300 2-In-1 Firmware, Dell Latitude 5300 2-In-1, Dell Latitude 5400 Firmware.