CVE-2020-5324

MEDIUMCVSS 4.4/10EPSS 0.25%

Last modified

CVE-2020-5324 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. EPSS estimates a 0.25% chance of exploitation in the next 30 days.

Description

Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.

Metrics

CVSS 3.1
4.4/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N

EPSS Probability
0.25%

16.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellG3 3579 Firmware< 1.11.0
DellG3 3779 Firmware< 1.11.0
DellG3 15 3590 Firmware< 1.9.2
DellG5 15 5590 Firmware< 1.11.1
DellG5 5090 Firmware< 1.1.2
DellG5 5587 Firmware< 1.12.2
DellG7 15 7590 Firmware< 1.11.1
DellG7 17 7790 Firmware< 1.11.1
DellG7 7588 Firmware< 1.12.2
DellInspiron 14 5490 Firmware< 1.4.0
DellInspiron 3480 Firmware< 1.7.0
DellInspiron 3481 Firmware< 1.6.0
DellInspiron 3490 Firmware< 1.5.0
DellInspiron 3493 Firmware< 1.4.0
DellInspiron 3580 Firmware< 1.7.0
DellInspiron 3581 Firmware< 1.6.0
DellInspiron 3583 Firmware< 1.7.0
DellInspiron 3584 Firmware< 1.6.0
DellInspiron 3590 Firmware< 1.5.0
DellInspiron 3593 Firmware< 1.4.0
DellInspiron 3780 Firmware< 1.7.0
DellInspiron 3781 Firmware< 1.6.0
DellInspiron 3790 Firmware< 1.5.0
DellInspiron 3793 Firmware< 1.4.0
DellInspiron 5390 Firmware< 1.7.1
DellInspiron 5391 Firmware< 1.3.0
DellInspiron 5480 Firmware< 2.6.1
DellInspiron 5481 Firmware< 2.6.1
DellInspiron 5482 Firmware<= 2.6.1
DellInspiron 5491 Firmware< 1.4.0
DellInspiron 5493 Firmware< 1.4.0
DellInspiron 5494 Firmware< 1.5.0
DellInspiron 5498 Firmware< 1.4.0
DellInspiron 5580 Firmware< 2.6.1
DellInspiron 5582 Firmware< 2.6.1
DellInspiron 5583 Firmware< 1.9.1
DellInspiron 5584 Firmware< 1.9.1
DellInspiron 5590 Firmware< 1.4.0
DellInspiron 5591 Firmware< 1.4.0
DellInspiron 5593 Firmware< 1.4.0
DellInspiron 5594 Firmware< 1.5.0
DellInspiron 5598 Firmware< 1.4.0
DellInspiron 7380 Firmware< 1.10.0
DellInspiron 7386 Firmware< 1.7.0
DellInspiron 7390 Firmware< 1.7.1
DellInspiron 7391 Firmware< 1.3.0
DellInspiron 7490 Firmware< 1.2.1
DellInspiron 7580 Firmware< 1.10.0
DellInspiron 7586 Firmware< 1.7.0
DellInspiron 7590 Firmware< 1.5.1

Showing 50 of 113 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-5324?
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.
How severe is CVE-2020-5324?
CVE-2020-5324 has a CVSS score of 4.4/10 (MEDIUM severity). The EPSS model estimates a 0.25% probability of exploitation in the next 30 days.
How do I fix CVE-2020-5324?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-5324?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST