CVE-2025-36579

MEDIUMCVSS 5.1/10EPSS 0.18%

Last modified

CVE-2025-36579 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.

Metrics

CVSS 3.1
5.1/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

EPSS Probability
0.18%

7.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
DellDell Pro 14 Essential PV14250< 1.4.0
DellDell Pro Micro / QCM1255< 1.9.1
DellDell Pro Slim / QCS1255< 1.9.1
DellDell Pro Tower / QCT1255< 1.9.1
DellAlienware 16 Area-51 AA16250< 1.9.0
DellAlienware 16X Aurora AC16251< 1.8.1
DellAlienware 18 Area-51 AA18250< 1.9.0
DellAlienware Area-51 AAT225< 1.11.0
DellAlienware Aurora ACT1250< 1.10.0
DellAlienware m15 R6< 1.42.0
DellAlienware m15 R7< 1.37.0
DellAlienware m16 R1< 1.32.0
DellAlienware m16 R2< 1.18.0
DellAlienware m18 R1< 1.32.0
DellAlienware M18 R2< 1.20.0
DellAlienware x14 R2< 1.30.1
DellAlienware x16 R1< 1.30.1
DellAlienware X16 R2< 1.18.1
DellChengMing 3900< 1.37.0
DellChengMing 3910/3911< 1.32.0
DellChengMing 3990< 1.35.1
DellChengMing 3991< 1.35.1
DellDell 14 DC14250< 1.4.0
DellDell 14 Premium DA14250< 1.5.1
DellDell 15 DC15250< 1.6.0
DellDell 16 DC16250< 1.7.0
DellDell 16 DC16251< 1.7.0
DellDell 16 Premium DA16250< 1.7.0
DellDell G15 5510< 1.38.0
DellDell G15 5511< 1.41.0
DellDell G15 5520< 1.38.0
DellDell G15 5530< 1.30.0
DellDell G16 7620< 1.38.0
DellDell G16 7630< 1.30.0
DellDell G5 5000< 1.28.2
DellDell Pro 13 Plus PB13250< 2.8.1
DellDell Pro 13 Plus PB13255< 1.9.1
DellDell Pro 13 Premium PA13250< 2.8.1
DellDell Pro 14 PC14250< 1.10.2
DellDell Pro 14 Plus PB14250< 2.8.1
DellDell Pro 14 Plus PB14255< 1.9.1
DellDell Pro 14 Premium PA14250< 2.8.1
DellDell Pro 15 Essential PV15250< 1.2.0
DellDell Pro 16 PC16250< 1.10.2
DellDell Pro 16 Plus PB16250< 2.8.1
DellDell Pro 16 Plus PB16255< 1.9.1
DellDell Pro 24 All-in-One Plus/Dell Pro 24 All-in-One< 1.10.1
DellDell Pro Laptop PC14250< 1.10.2
DellDell Pro Laptop PC16250< 1.10.2
DellDell Pro Max 14 MC14250< 1.9.0

Showing 50 of 120 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2025-36579?
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.
How severe is CVE-2025-36579?
CVE-2025-36579 has a CVSS score of 5.1/10 (MEDIUM severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2025-36579?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-36579?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST