CVE-2019-3717

MEDIUMCVSS 6.8/10EPSS 0.36%

Last modified

CVE-2019-3717 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. EPSS estimates a 0.36% chance of exploitation in the next 30 days.

Description

Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.36%

28.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
DellChengming 3967 Firmware< 1.5.0
DellChengming 3977 Firmware< 1.6.0
DellChengming 3980 Firmware< 1.5.21
DellG3 3579 Firmware< 1.9.0
DellG3 3779 Firmware< 1.9.0
DellG5 5587 Firmware< 1.10.0
DellG5 5590 Firmware< 1.3.1
DellG7 7588 Firmware< 1.10.0
DellG7 7590 Firmware< 1.3.1
DellG7 7790 Firmware< 1.3.1
DellEmbedded Box Pc 5000 Firmware< 1.5.6
DellInspiron 3153 Firmware< 1.22.0
DellInspiron 3158 Firmware< 1.22.0
DellInspiron 5368 Firmware< 1.19.0
DellInspiron 5378 Firmware< 1.27.0
DellInspiron 5379 Firmware< 1.11.0
DellInspiron 7353 Firmware< 1.22.0
DellInspiron 7359 Firmware< 1.22.0
DellInspiron 7368 Firmware< 1.19.0
DellInspiron 7373 Firmware< 1.13.1
DellInspiron 7378 Firmware< 1.27.0
DellInspiron 7370 Firmware< 1.13.1
DellInspiron 3459 Firmware< 1.9.0
DellInspiron 3467 Firmware< 2.9.0
DellInspiron 3468 Firmware< 1.12.0
DellInspiron 5468 Firmware< 1.9.1
DellInspiron 7460 Firmware< 1.10.0
DellInspiron 7466 Firmware< 1.4.0
DellInspiron 7467 Firmware< 1.9.0
DellInspiron 3458 Firmware< a18
DellInspiron 3559 Firmware< 1.9.0
DellInspiron 3567 Firmware< 2.9.0
DellInspiron 3568 Firmware< 1.12.0
DellInspiron 5566 Firmware< 1.9.1
DellInspiron 5567 Firmware< 1.2.7
DellInspiron 7560 Firmware< 1.10.0
DellInspiron 5568 Firmware< 1.19.0
DellInspiron 5578 Firmware< 1.27.0
DellInspiron 5579 Firmware< 1.11.0
DellInspiron 7568 Firmware< 1.22.0
DellInspiron 7569 Firmware< 1.19.0
DellInspiron 7573 Firmware< 1.13.1
DellInspiron 7579 Firmware< 1.27.0
DellInspiron 7570 Firmware< 1.13.1
DellInspiron 7566 Firmware< 1.4.0
DellInspiron 7567 Firmware< 1.9.0
DellInspiron 7577 Firmware< 1.7.0
DellInspiron 3558 Firmware< a18
DellInspiron 5767 Firmware< 1.2.7
DellInspiron 7773 Firmware< 1.11.0

Showing 50 of 241 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-3717?
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.
How severe is CVE-2019-3717?
CVE-2019-3717 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.36% probability of exploitation in the next 30 days.
How do I fix CVE-2019-3717?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-3717?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST