7.1

CVE-2020-5324

Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellG3 3579 Firmware Version < 1.11.0
   DellG3 3579 Version-
DellG3 3779 Firmware Version < 1.11.0
   DellG3 3779 Version-
DellG3 15 3590 Firmware Version < 1.9.2
   DellG3 15 3590 Version-
DellG5 15 5590 Firmware Version < 1.11.1
   DellG5 15 5590 Version-
DellG5 5090 Firmware Version < 1.1.2
   DellG5 5090 Version-
DellG5 5587 Firmware Version < 1.12.2
   DellG5 5587 Version-
DellG7 15 7590 Firmware Version < 1.11.1
   DellG7 15 7590 Version-
DellG7 17 7790 Firmware Version < 1.11.1
   DellG7 17 7790 Version-
DellG7 7588 Firmware Version < 1.12.2
   DellG7 7588 Version-
DellInspiron 14 5490 Firmware Version < 1.4.0
   DellInspiron 14 5490 Version-
DellInspiron 3480 Firmware Version < 1.7.0
   DellInspiron 3480 Version-
DellInspiron 3481 Firmware Version < 1.6.0
   DellInspiron 3481 Version-
DellInspiron 3490 Firmware Version < 1.5.0
   DellInspiron 3490 Version-
DellInspiron 3493 Firmware Version < 1.4.0
   DellInspiron 3493 Version-
DellInspiron 3580 Firmware Version < 1.7.0
   DellInspiron 3580 Version-
DellInspiron 3581 Firmware Version < 1.6.0
   DellInspiron 3581 Version-
DellInspiron 3583 Firmware Version < 1.7.0
   DellInspiron 3583 Version-
DellInspiron 3584 Firmware Version < 1.6.0
   DellInspiron 3584 Version-
DellInspiron 3590 Firmware Version < 1.5.0
   DellInspiron 3590 Version-
DellInspiron 3593 Firmware Version < 1.4.0
   DellInspiron 3593 Version-
DellInspiron 3780 Firmware Version < 1.7.0
   DellInspiron 3780 Version-
DellInspiron 3781 Firmware Version < 1.6.0
   DellInspiron 3781 Version-
DellInspiron 3790 Firmware Version < 1.5.0
   DellInspiron 3790 Version-
DellInspiron 3793 Firmware Version < 1.4.0
   DellInspiron 3793 Version-
DellInspiron 5390 Firmware Version < 1.7.1
   DellInspiron 5390 Version-
DellInspiron 5391 Firmware Version < 1.3.0
   DellInspiron 5391 Version-
DellInspiron 5480 Firmware Version < 2.6.1
   DellInspiron 5480 Version-
DellInspiron 5481 Firmware Version < 2.6.1
   DellInspiron 5481 Version-
DellInspiron 5482 Firmware Version <= 2.6.1
   DellInspiron 5482 Version-
DellInspiron 5491 Firmware Version < 1.4.0
   DellInspiron 5491 Version-
DellInspiron 5493 Firmware Version < 1.4.0
   DellInspiron 5493 Version-
DellInspiron 5494 Firmware Version < 1.5.0
   DellInspiron 5494 Version-
DellInspiron 5498 Firmware Version < 1.4.0
   DellInspiron 5498 Version-
DellInspiron 5580 Firmware Version < 2.6.1
   DellInspiron 5580 Version-
DellInspiron 5582 Firmware Version < 2.6.1
   DellInspiron 5582 Version-
DellInspiron 5583 Firmware Version < 1.9.1
   DellInspiron 5583 Version-
DellInspiron 5584 Firmware Version < 1.9.1
   DellInspiron 5584 Version-
DellInspiron 5590 Firmware Version < 1.4.0
   DellInspiron 5590 Version-
DellInspiron 5591 Firmware Version < 1.4.0
   DellInspiron 5591 Version-
DellInspiron 5593 Firmware Version < 1.4.0
   DellInspiron 5593 Version-
DellInspiron 5594 Firmware Version < 1.5.0
   DellInspiron 5594 Version-
DellInspiron 5598 Firmware Version < 1.4.0
   DellInspiron 5598 Version-
DellInspiron 7380 Firmware Version < 1.10.0
   DellInspiron 7380 Version-
DellInspiron 7386 Firmware Version < 1.7.0
   DellInspiron 7386 Version-
DellInspiron 7390 Firmware Version < 1.7.1
   DellInspiron 7390 Version-
DellInspiron 7391 Firmware Version < 1.3.0
   DellInspiron 7391 Version-
DellInspiron 7490 Firmware Version < 1.2.1
   DellInspiron 7490 Version-
DellInspiron 7580 Firmware Version < 1.10.0
   DellInspiron 7580 Version-
DellInspiron 7586 Firmware Version < 1.7.0
   DellInspiron 7586 Version-
DellInspiron 7590 Firmware Version < 1.5.1
   DellInspiron 7590 Version-
DellInspiron 7591 Firmware Version < 1.5.1
   DellInspiron 7591 Version-
DellInspiron 7786 Firmware Version < 1.7.0
   DellInspiron 7786 Version-
DellInspiron 7791 Firmware Version < 1.3.1
   DellInspiron 7791 Version-
DellLatitude 3301 Firmware Version < 1.7.0
   DellLatitude 3301 Version-
DellLatitude 3300 Firmware Version < 1.7.2
   DellLatitude 3300 Version-
DellLatitude 3311 Firmware Version < 1.3.0
   DellLatitude 3311 Version-
DellLatitude 3390 Firmware Version < 1.12.0
   DellLatitude 3390 Version-
DellLatitude 3400 Firmware Version < 1.9.2
   DellLatitude 3400 Version-
DellLatitude 3490 Firmware Version < 1.11.0
   DellLatitude 3490 Version-
DellLatitude 3500 Firmware Version < 1.9.2
   DellLatitude 3500 Version-
DellLatitude 3590 Firmware Version < 1.11.0
   DellLatitude 3590 Version-
DellLatitude 5290 Firmware Version < 1.12.1
   DellLatitude 5290 Version-
DellLatitude 5300 Firmware Version < 1.7.2
   DellLatitude 5300 Version-
DellLatitude 5400 Firmware Version < 1.6.3
   DellLatitude 5400 Version-
DellLatitude 5401 Firmware Version < 1.6.1
   DellLatitude 5401 Version-
DellLatitude 5420 Rugged Firmware Version < 1.8.5
   DellLatitude 5420 Rugged Version-
DellLatitude 5424 Rugged Firmware Version < 1.8.5
   DellLatitude 5424 Rugged Version-
DellLatitude 5490 Firmware Version < 1.12.1
   DellLatitude 5490 Version-
DellLatitude 5491 Firmware Version < 1.11.1
   DellLatitude 5491 Version-
DellLatitude 5500 Firmware Version < 1.6.3
   DellLatitude 5500 Version-
DellLatitude 5501 Firmware Version < 1.6.1
   DellLatitude 5501 Version-
DellLatitude 5590 Firmware Version < 1.12.1
   DellLatitude 5590 Version-
DellLatitude 5591 Firmware Version < 1.11.1
   DellLatitude 5591 Version-
DellLatitude 7200 Firmware Version < 1.6.2
   DellLatitude 7200 Version-
DellLatitude 7290 Firmware Version < 1.13.1
   DellLatitude 7290 Version-
DellLatitude 7300 Firmware Version < 1.6.1
   DellLatitude 7300 Version-
DellLatitude 7390 Firmware Version < 1.13.1
   DellLatitude 7390 Version-
DellLatitude 7400 Firmware Version < 1.6.1
   DellLatitude 7400 Version-
DellLatitude 7490 Firmware Version < 1.13.1
   DellLatitude 7490 Version-
DellPrecision 3530 Firmware Version < 1.11.1
   DellPrecision 3530 Version-
DellPrecision 3540 Firmware Version < 1.6.3
   DellPrecision 3540 Version-
DellPrecision 3541 Firmware Version < 1.6.1
   DellPrecision 3541 Version-
DellPrecision 5530 Firmware Version < 1.14.0
   DellPrecision 5530 Version-
DellPrecision 5540 Firmware Version < 1.6.3
   DellPrecision 5540 Version-
DellPrecision 7530 Firmware Version < 1.12.1
   DellPrecision 7530 Version-
DellPrecision 7540 Firmware Version < 1.5.1
   DellPrecision 7540 Version-
DellPrecision 7730 Firmware Version < 1.12.1
   DellPrecision 7730 Version-
DellPrecision 7740 Firmware Version < 1.5.1
   DellPrecision 7740 Version-
DellVostro 15 7580 Firmware Version < 1.12.2
   DellVostro 15 7580 Version-
DellVostro 3480 Firmware Version < 1.7.0
   DellVostro 3480 Version-
DellVostro 3481 Firmware Version < 1.6.0
   DellVostro 3481 Version-
DellVostro 3490 Firmware Version < 1.5.0
   DellVostro 3490 Version-
DellVostro 3580 Firmware Version < 1.7.0
   DellVostro 3580 Version-
DellVostro 3581 Firmware Version < 1.6.0
   DellVostro 3581 Version-
DellVostro 3583 Firmware Version < 1.7.0
   DellVostro 3583 Version-
DellVostro 3584 Firmware Version < 1.6.0
   DellVostro 3584 Version-
DellVostro 3590 Firmware Version < 1.5.0
   DellVostro 3590 Version-
DellVostro 5390 Firmware Version < 1.7.1
   DellVostro 5390 Version-
DellVostro 5391 Firmware Version < 1.3.0
   DellVostro 5391 Version-
DellVostro 5481 Firmware Version < 2.6.1
   DellVostro 5481 Version-
DellVostro 5490 Firmware Version < 1.4.0
   DellVostro 5490 Version-
DellVostro 5581 Firmware Version < 2.6.1
   DellVostro 5581 Version-
DellVostro 5590 Firmware Version < 1.4.0
   DellVostro 5590 Version-
DellVostro 7590 Firmware Version < 1.5.1
   DellVostro 7590 Version-
DellWyse 5070 Thin Client Firmware Version < 1.4.2
   DellWyse 5070 Thin Client Version-
DellWyse 5470 Firmware Version < 1.2.1
   DellWyse 5470 Version-
DellXps 13 9380 Firmware Version < 1.9.1
   DellXps 13 9380 Version-
DellXps 15 9575 Firmware Version < 1.10.0
   DellXps 15 9575 Version-
DellXps 15 7590 Firmware Version < 1.4.0
   DellXps 15 7590 Version-
DellXps 15 9570 Firmware Version < 1.14.0
   DellXps 15 9570 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.283
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
nvd@nist.gov 2.6 1.9 4.9
AV:L/AC:H/Au:N/C:N/I:P/A:P
security_alert@emc.com 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.