SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-3717

Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability.

MEDIUM 6.8EPSS 0.36%

Does this matter?

Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.

Description

Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.36% probability · 30th percentile
CISA KEV
Not listed
Affected
dell/chengming 3967 firmware · dell/chengming 3977 firmware · dell/chengming 3980 firmware · dell/g3 3579 firmware · dell/g3 3779 firmware · dell/g5 5587 firmware · dell/g5 5590 firmware · dell/g7 7588 firmware · dell/g7 7590 firmware · dell/g7 7790 firmware · dell/embedded box pc 5000 firmware · dell/inspiron 3153 firmware · dell/inspiron 3158 firmware · dell/inspiron 5368 firmware · dell/inspiron 5378 firmware · dell/inspiron 5379 firmware · dell/inspiron 7353 firmware · dell/inspiron 7359 firmware · dell/inspiron 7368 firmware · dell/inspiron 7373 firmware · +40 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.