CVE-2025-36579
Last modified
CVE-2025-36579 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Dell | Dell Pro 14 Essential PV14250 | < 1.4.0 |
| Dell | Dell Pro Micro / QCM1255 | < 1.9.1 |
| Dell | Dell Pro Slim / QCS1255 | < 1.9.1 |
| Dell | Dell Pro Tower / QCT1255 | < 1.9.1 |
| Dell | Alienware 16 Area-51 AA16250 | < 1.9.0 |
| Dell | Alienware 16X Aurora AC16251 | < 1.8.1 |
| Dell | Alienware 18 Area-51 AA18250 | < 1.9.0 |
| Dell | Alienware Area-51 AAT225 | < 1.11.0 |
| Dell | Alienware Aurora ACT1250 | < 1.10.0 |
| Dell | Alienware m15 R6 | < 1.42.0 |
| Dell | Alienware m15 R7 | < 1.37.0 |
| Dell | Alienware m16 R1 | < 1.32.0 |
| Dell | Alienware m16 R2 | < 1.18.0 |
| Dell | Alienware m18 R1 | < 1.32.0 |
| Dell | Alienware M18 R2 | < 1.20.0 |
| Dell | Alienware x14 R2 | < 1.30.1 |
| Dell | Alienware x16 R1 | < 1.30.1 |
| Dell | Alienware X16 R2 | < 1.18.1 |
| Dell | ChengMing 3900 | < 1.37.0 |
| Dell | ChengMing 3910/3911 | < 1.32.0 |
| Dell | ChengMing 3990 | < 1.35.1 |
| Dell | ChengMing 3991 | < 1.35.1 |
| Dell | Dell 14 DC14250 | < 1.4.0 |
| Dell | Dell 14 Premium DA14250 | < 1.5.1 |
| Dell | Dell 15 DC15250 | < 1.6.0 |
| Dell | Dell 16 DC16250 | < 1.7.0 |
| Dell | Dell 16 DC16251 | < 1.7.0 |
| Dell | Dell 16 Premium DA16250 | < 1.7.0 |
| Dell | Dell G15 5510 | < 1.38.0 |
| Dell | Dell G15 5511 | < 1.41.0 |
| Dell | Dell G15 5520 | < 1.38.0 |
| Dell | Dell G15 5530 | < 1.30.0 |
| Dell | Dell G16 7620 | < 1.38.0 |
| Dell | Dell G16 7630 | < 1.30.0 |
| Dell | Dell G5 5000 | < 1.28.2 |
| Dell | Dell Pro 13 Plus PB13250 | < 2.8.1 |
| Dell | Dell Pro 13 Plus PB13255 | < 1.9.1 |
| Dell | Dell Pro 13 Premium PA13250 | < 2.8.1 |
| Dell | Dell Pro 14 PC14250 | < 1.10.2 |
| Dell | Dell Pro 14 Plus PB14250 | < 2.8.1 |
| Dell | Dell Pro 14 Plus PB14255 | < 1.9.1 |
| Dell | Dell Pro 14 Premium PA14250 | < 2.8.1 |
| Dell | Dell Pro 15 Essential PV15250 | < 1.2.0 |
| Dell | Dell Pro 16 PC16250 | < 1.10.2 |
| Dell | Dell Pro 16 Plus PB16250 | < 2.8.1 |
| Dell | Dell Pro 16 Plus PB16255 | < 1.9.1 |
| Dell | Dell Pro 24 All-in-One Plus/Dell Pro 24 All-in-One | < 1.10.1 |
| Dell | Dell Pro Laptop PC14250 | < 1.10.2 |
| Dell | Dell Pro Laptop PC16250 | < 1.10.2 |
| Dell | Dell Pro Max 14 MC14250 | < 1.9.0 |
Showing 50 of 120 affected configurations. See the CNA advisory for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2025-36579?
How severe is CVE-2025-36579?
How do I fix CVE-2025-36579?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-36573Dell Smart Dock Firmware, versions prior to 01.00.08.01, con…5.5
- CVE-2025-36574Dell Wyse Management Suite, versions prior to WMS 5.2, conta…8.2
- CVE-2025-36575Dell Wyse Management Suite, versions prior to WMS 5.2, conta…7.5
- CVE-2025-36576Dell Wyse Management Suite, versions prior to WMS 5.2, conta…2.7
- CVE-2025-36577Dell Wyse Management Suite, versions prior to WMS 5.2, conta…6.1
- CVE-2025-36578Dell Wyse Management Suite, versions prior to WMS 5.2, conta…6.8
- CVE-2025-36580Dell Wyse Management Suite, versions prior to WMS 5.2, conta…4.8
- CVE-2025-36581Dell PowerEdge Platform version(s) 14G AMD BIOS v1.25.0 and …5.5
- CVE-2025-36582Dell NetWorker, versions 19.12.0.1 and prior, contains a Sel…7.5
- CVE-2025-36588Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s)…8.8
- CVE-2025-36589Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) …7.1
- CVE-2025-3659Improper authentication handling was identified in a set of …9.4
Are you affected by CVE-2025-36579?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
