4.4

CVE-2025-29989

Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellPrecision 5820 Tower Firmware Version < 2.42.0
   DellPrecision 5820 Tower Version-
DellPrecision 7820 Tower Firmware Version < 2.46.0
   DellPrecision 7820 Tower Version-
DellPrecision 7920 Tower Firmware Version < 2.46.0
   DellPrecision 7920 Tower Version-
DellPrecision 7865 Tower Firmware Version < 1.18.0
   DellPrecision 7865 Tower Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.161
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
security_alert@emc.com 3.1 0.6 2.5
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L
CWE-1328 Security Version Number Mutable to Older Versions

Security-version number in hardware is mutable, resulting in the ability to downgrade (roll-back) the boot firmware to vulnerable code versions.