CVE-2020-5362

Published Jun 10, 2020

Last updated 3 months ago

Overview

Description
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.
Source
security_alert@emc.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
4.4
Impact score
3.6
Exploitability score
0.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
2.1
Impact score
2.9
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:N/I:P/A:N

Weaknesses

security_alert@emc.com
CWE-285
nvd@nist.gov
CWE-862

Social media

Hype score
Not currently trending

Configurations