CVE-2020-5326

MEDIUMCVSS 5.3/10EPSS 0.35%

Last modified

CVE-2020-5326 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring the BIOS Admin password by selecting the Optimized Defaults option in the pre-boot iRST Manager.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.

Description

Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring the BIOS Admin password by selecting the Optimized Defaults option in the pre-boot iRST Manager.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

EPSS Probability
0.35%

26.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellChengming 3980 Firmware< 2.13.0
DellG3 3579 Firmware< 1.10.0
DellG3 3590 Firmware< 1.4.3
DellG3 3779 Firmware< 1.10.0
DellG5 5587 Firmware< 1.11.1
DellG5 5590 Firmware< 1.8.0
DellG7 7588 Firmware< 1.11.1
DellG7 7590 Firmware< 1.8.0
DellG7 7790 Firmware< 1.8.0
DellEmbedded Box Pc 5000 Firmware< 1.6.0
DellInspiron 14 Gaming 7466 Firmware< 1.5.0
DellInspiron 14 Gaming 7467 Firmware< 1.10.0
DellInspiron 15 7572 Firmware< 1.2.1
DellInspiron 15 Gaming 7566 Firmware< 1.5.0
DellInspiron 15 Gaming 7567 Firmware< 1.10.0
DellInspiron 15 Gaming 7577 Firmware< 1.8.0
DellInspiron 3470 Firmware< 2.13.0
DellInspiron 3480 Firmware< 1.5.1
DellInspiron 3481 Firmware< 1.4.0
DellInspiron 3580 Firmware< 1.5.1
DellInspiron 3581 Firmware< 1.4.0
DellInspiron 3583 Firmware< 1.5.1
DellInspiron 3584 Firmware< 1.4.0
DellInspiron 3670 Firmware< 2.13.0
DellInspiron 3780 Firmware< 1.5.1
DellInspiron 3781 Firmware< 1.4.0
DellInspiron 5370 Firmware< 1.12.0
DellInspiron 5480 Firmware< 2.4.0
DellInspiron 5481 Firmware< 2.4.0
DellInspiron 5482 Firmware< 2.4.0
DellInspiron 5488 Firmware< 2.4.0
DellInspiron 5570 Firmware< 1.2.3
DellInspiron 5580 Firmware< 2.4.0
DellInspiron 5582 Firmware< 2.4.0
DellInspiron 5770 Firmware< 1.2.3
DellInspiron 7380 Firmware< 1.8.0
DellInspiron 7386 Firmware< 1.5.0
DellInspiron 7472 Firmware< 1.2.1
DellInspiron 7580 Firmware< 1.8.0
DellInspiron 7586 Firmware< 1.5.0
DellInspiron 7590 Firmware< 1.1.1
DellInspiron 7591 Firmware< 1.1.1
DellInspiron 7786 Firmware< 1.5.0
DellLatitude 3300 Firmware< 1.4.0
DellLatitude 3460 Firmware< a17
DellLatitude 3480 Firmware< 1.12.0
DellLatitude 3490 Firmware< 1.9.9
DellLatitude 3580 Firmware< 1.12.0
DellLatitude 3590 Firmware< 1.9.9
DellLatitude 5175 Firmware< 1.7.1

Showing 50 of 174 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-5326?
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring the BIOS Admin password by selecting the Optimized Defaults option in the pre-boot iRST Manager.
How severe is CVE-2020-5326?
CVE-2020-5326 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2020-5326?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-5326?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST