CVE-2020-5362
Last modified
CVE-2020-5362 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Chengming 3967 Firmware | < 1.9.0 |
| Dell | Chengming 3977 Firmware | < 1.9.0 |
| Dell | Chengming 3980 Firmware | < 2.16.0 |
| Dell | Chengming 3988 Firmware | < 1.3.0 |
| Dell | Chengming 3990 Firmware | < 1.1.3 |
| Dell | Chengming 3991 Firmware | < 1.1.3 |
| Dell | G3 15 3500 Firmware | < 1.2.1 |
| Dell | G3 15 3590 Firmware | < 1.11.0 |
| Dell | G3 3579 Firmware | < 1.13.0 |
| Dell | G3 3779 Firmware | < 1.13.0 |
| Dell | G5 15 5500 Firmware | < 1.2.1 |
| Dell | G5 15 5590 Firmware | < 1.13.2 |
| Dell | G5 5587 Firmware | < 1.14.0 |
| Dell | G7 15 7590 Firmware | < 1.13.2 |
| Dell | G7 17 7790 Firmware | < 1.13.2 |
| Dell | G7 7588 Firmware | < 1.14.0 |
| Dell | Embedded Box Pc 5000 Firmware | < 1.8.0 |
| Dell | G5 5090 Firmware | < 1.3.0 |
| Dell | Inspiron 11 2-In-1 3153 Firmware | < 1.25.0 |
| Dell | Inspiron 11 2-In-1 3158 Firmware | < 1.25.0 |
| Dell | Inspiron 13 7370 Firmware | < 1.17.0 |
| Dell | Inspiron 13 2-In-1 5368 Firmware | < 1.22.0 |
| Dell | Inspiron 13 2-In-1 5378 Firmware | < 1.30.0 |
| Dell | Inspiron 13 2-In-1 5379 Firmware | < 1.14.0 |
| Dell | Inspiron 13 2-In-1 7353 Firmware | < 1.25.0 |
| Dell | Inspiron 13 2-In-1 7359 Firmware | < 1.25.0 |
| Dell | Inspiron 13 2-In-1 7368 Firmware | < 1.22.0 |
| Dell | Inspiron 13 2-In-1 7373 Firmware | < 1.17.0 |
| Dell | Inspiron 13 2-In-1 7378 Firmware | < 1.30.0 |
| Dell | Inspiron 14 3458 Firmware | < a21 |
| Dell | Inspiron 14 3459 Firmware | < 1.12.0 |
| Dell | Inspiron 14 3467 Firmware | < 2.12.0 |
| Dell | Inspiron 14 3468 Firmware | < 1.15.0 |
| Dell | Inspiron 14 3473 Firmware | < 1.9.0 |
| Dell | Inspiron 14 5468 Firmware | < 1.12.1 |
| Dell | Inspiron 14 5490 Firmware | < 1.10.0 |
| Dell | Inspiron 14 7460 Firmware | < 1.13.2 |
| Dell | Inspiron 14 Gaming 7466 Firmware | < 1.7.0 |
| Dell | Inspiron 14 Gaming 7467 Firmware | < 1.12.1 |
| Dell | Inspiron 15 3559 Firmware | < 1.12.0 |
| Dell | Inspiron 15 3567 Firmware | < 2.12.0 |
| Dell | Inspiron 15 3568 Firmware | < 1.15.0 |
| Dell | Inspiron 15 5566 Firmware | < 1.12.1 |
| Dell | Inspiron 15 5567 Firmware | < 1.2.11 |
| Dell | Inspiron 15 7560 Firmware | < 1.13.2 |
| Dell | Inspiron 15 7570 Firmware | < 1.17.0 |
| Dell | Inspiron 15 7572 Firmware | < 1.5.2 |
| Dell | Inspiron 15 2-In-1 5568 Firmware | < 1.22.0 |
| Dell | Inspiron 15 2-In-1 5578 Firmware | < 1.30.0 |
| Dell | Inspiron 15 2-In-1 5579 Firmware | < 1.14.0 |
Showing 50 of 354 affected configurations. See NVD for the full list.
References
- https://www.dell.com/support/article/SLN321726Vendor Advisory
- https://www.dell.com/support/article/SLN321726Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5362?
How severe is CVE-2020-5362?
How do I fix CVE-2020-5362?
Are you affected by CVE-2020-5362?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
