8.6

CVE-2020-5363

Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially allow an unauthorized actor, with physical access and/or OS administrator privileges to the device, to gain privileged access to the platform and the hard drive.

Data is provided by the National Vulnerability Database (NVD)
DellLatitude 5300 Firmware Version < 1.9.4
   DellLatitude 5300 Version-
DellLatitude 5300 2-in-1 Firmware Version < 1.9.4
   DellLatitude 5300 2-in-1 Version-
DellLatitude 5400 Firmware Version < 1.7.4
   DellLatitude 5400 Version-
DellLatitude 5401 Firmware Version < 1.8.4
   DellLatitude 5401 Version-
DellLatitude 5500 Firmware Version < 1.7.4
   DellLatitude 5500 Version-
DellLatitude 5501 Firmware Version < 1.8.4
   DellLatitude 5501 Version-
DellLatitude 7200 2 In 1 Firmware Version < 1.8.0
   DellLatitude 7200 2 In 1 Version-
DellLatitude 7220 Firmware Version < 1.6.0
   DellLatitude 7220 Version-
DellLatitude 7300 Firmware Version < 1.7.4
   DellLatitude 7300 Version-
DellLatitude 7400 Firmware Version < 1.7.4
   DellLatitude 7400 Version-
DellPrecision 3540 Firmware Version < 1.7.4
   DellPrecision 3540 Version-
DellPrecision 3541 Firmware Version < 1.8.4
   DellPrecision 3541 Version-
DellPrecision 7540 Firmware Version < 1.9.0
   DellPrecision 7540 Version-
DellPrecision 7740 Firmware Version < 1.9.0
   DellPrecision 7740 Version-
DellXps 13 9300 Firmware Version < 1.0.11
   DellXps 13 9300 Version-
DellXps 7390 2-in-1 Firmware Version < 1.4.0
   DellXps 7390 2-in-1 Version-
DellXps 7590 Firmware Version < 1.7.0
   DellXps 7590 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.118
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
security_alert@emc.com 8.6 1.8 6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE-158 Improper Neutralization of Null Byte or NUL Character

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.