CVE-2019-3717
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability.
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- dell/chengming 3967 firmware · dell/chengming 3977 firmware · dell/chengming 3980 firmware · dell/g3 3579 firmware · dell/g3 3779 firmware · dell/g5 5587 firmware · dell/g5 5590 firmware · dell/g7 7588 firmware · dell/g7 7590 firmware · dell/g7 7790 firmware · dell/embedded box pc 5000 firmware · dell/inspiron 3153 firmware · dell/inspiron 3158 firmware · dell/inspiron 5368 firmware · dell/inspiron 5378 firmware · dell/inspiron 5379 firmware · dell/inspiron 7353 firmware · dell/inspiron 7359 firmware · dell/inspiron 7368 firmware · dell/inspiron 7373 firmware · +40 more
- Source
- security_alert@emc.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.