CVE-2020-5362
—CVSS 3.1
4.4 medium
EPSS
<1%p21
Published
()
Modified
Description
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.
- Vendors
- dell
- Products
- chengming 3967 firmware, chengming 3977 firmware, chengming 3980 firmware, chengming 3988 firmware, chengming 3990 firmware, chengming 3991 firmware, g3 15 3500 firmware, g3 15 3590 firmware, g3 3579 firmware, g3 3779 firmware, g5 15 5500 firmware, g5 15 5590 firmware
- Weakness
- CWE-285, CWE-862
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.