ZeroHour

CVE-2019-3717

CVSS 3.1
6.8 medium
EPSS
<1%p30
Published
()
Modified
Description

Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.

Vendors
dell
Products
chengming 3967 firmware, chengming 3977 firmware, chengming 3980 firmware, g3 3579 firmware, g3 3779 firmware, g5 5587 firmware, g5 5590 firmware, g7 7588 firmware, g7 7590 firmware, g7 7790 firmware, embedded box pc 5000 firmware, inspiron 3153 firmware
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.