ZeroHour

CVE-2020-5362

CVSS 3.1
4.4 medium
EPSS
<1%p21
Published
()
Modified
Description

Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.

Vendors
dell
Products
chengming 3967 firmware, chengming 3977 firmware, chengming 3980 firmware, chengming 3988 firmware, chengming 3990 firmware, chengming 3991 firmware, g3 15 3500 firmware, g3 15 3590 firmware, g3 3579 firmware, g3 3779 firmware, g5 15 5500 firmware, g5 15 5590 firmware
Weakness
CWE-285, CWE-862
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.