CVE-2020-5362
Last modified
CVE-2020-5362 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Chengming 3967 Firmware | < 1.9.0 |
| Dell | Chengming 3977 Firmware | < 1.9.0 |
| Dell | Chengming 3980 Firmware | < 2.16.0 |
| Dell | Chengming 3988 Firmware | < 1.3.0 |
| Dell | Chengming 3990 Firmware | < 1.1.3 |
| Dell | Chengming 3991 Firmware | < 1.1.3 |
| Dell | G3 15 3500 Firmware | < 1.2.1 |
| Dell | G3 15 3590 Firmware | < 1.11.0 |
| Dell | G3 3579 Firmware | < 1.13.0 |
| Dell | G3 3779 Firmware | < 1.13.0 |
| Dell | G5 15 5500 Firmware | < 1.2.1 |
| Dell | G5 15 5590 Firmware | < 1.13.2 |
| Dell | G5 5587 Firmware | < 1.14.0 |
| Dell | G7 15 7590 Firmware | < 1.13.2 |
| Dell | G7 17 7790 Firmware | < 1.13.2 |
| Dell | G7 7588 Firmware | < 1.14.0 |
| Dell | Embedded Box Pc 5000 Firmware | < 1.8.0 |
| Dell | G5 5090 Firmware | < 1.3.0 |
| Dell | Inspiron 11 2-In-1 3153 Firmware | < 1.25.0 |
| Dell | Inspiron 11 2-In-1 3158 Firmware | < 1.25.0 |
| Dell | Inspiron 13 7370 Firmware | < 1.17.0 |
| Dell | Inspiron 13 2-In-1 5368 Firmware | < 1.22.0 |
| Dell | Inspiron 13 2-In-1 5378 Firmware | < 1.30.0 |
| Dell | Inspiron 13 2-In-1 5379 Firmware | < 1.14.0 |
| Dell | Inspiron 13 2-In-1 7353 Firmware | < 1.25.0 |
| Dell | Inspiron 13 2-In-1 7359 Firmware | < 1.25.0 |
| Dell | Inspiron 13 2-In-1 7368 Firmware | < 1.22.0 |
| Dell | Inspiron 13 2-In-1 7373 Firmware | < 1.17.0 |
| Dell | Inspiron 13 2-In-1 7378 Firmware | < 1.30.0 |
| Dell | Inspiron 14 3458 Firmware | < a21 |
| Dell | Inspiron 14 3459 Firmware | < 1.12.0 |
| Dell | Inspiron 14 3467 Firmware | < 2.12.0 |
| Dell | Inspiron 14 3468 Firmware | < 1.15.0 |
| Dell | Inspiron 14 3473 Firmware | < 1.9.0 |
| Dell | Inspiron 14 5468 Firmware | < 1.12.1 |
| Dell | Inspiron 14 5490 Firmware | < 1.10.0 |
| Dell | Inspiron 14 7460 Firmware | < 1.13.2 |
| Dell | Inspiron 14 Gaming 7466 Firmware | < 1.7.0 |
| Dell | Inspiron 14 Gaming 7467 Firmware | < 1.12.1 |
| Dell | Inspiron 15 3559 Firmware | < 1.12.0 |
| Dell | Inspiron 15 3567 Firmware | < 2.12.0 |
| Dell | Inspiron 15 3568 Firmware | < 1.15.0 |
| Dell | Inspiron 15 5566 Firmware | < 1.12.1 |
| Dell | Inspiron 15 5567 Firmware | < 1.2.11 |
| Dell | Inspiron 15 7560 Firmware | < 1.13.2 |
| Dell | Inspiron 15 7570 Firmware | < 1.17.0 |
| Dell | Inspiron 15 7572 Firmware | < 1.5.2 |
| Dell | Inspiron 15 2-In-1 5568 Firmware | < 1.22.0 |
| Dell | Inspiron 15 2-In-1 5578 Firmware | < 1.30.0 |
| Dell | Inspiron 15 2-In-1 5579 Firmware | < 1.14.0 |
Showing 50 of 354 affected configurations. See NVD for the full list.
References
- https://www.dell.com/support/article/SLN321726Vendor Advisory
- https://www.dell.com/support/article/SLN321726Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5362?
How severe is CVE-2020-5362?
How do I fix CVE-2020-5362?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-5356Dell PowerProtect Data Manager (PPDM) versions prior to 19.4…6.5
- CVE-2020-5357Dell Dock Firmware Update Utilities for Dell Client Consumer…6
- CVE-2020-5358Dell Encryption versions prior to 10.7 and Dell Endpoint Sec…7.8
- CVE-2020-5359Dell BSAFE Micro Edition Suite, versions prior to 4.5, are v…5.8
- CVE-2020-5360Dell BSAFE Micro Edition Suite, versions prior to 4.5, are v…7.5
- CVE-2020-5361Select Dell Client Commercial and Consumer platforms support…7.6
- CVE-2020-5363Select Dell Client Consumer and Commercial platforms include…6.7
- CVE-2020-5364Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an …7.5
- CVE-2020-5365Dell EMC Isilon versions 8.2.2 and earlier contain a remotes…7.5
- CVE-2020-5366Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path …6.5
- CVE-2020-5367Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, …8.1
- CVE-2020-5368Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an impr…7.5
Are you affected by CVE-2020-5362?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
