SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5324

Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability.

MEDIUM 4.4EPSS 0.25%

Does this matter?

Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.

Description

Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.

CVSS 3.1
4.4 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
EPSS
0.25% probability · 17th percentile
CISA KEV
Not listed
Weakness
CWE-427, CWE-59
Affected
dell/g3 3579 firmware · dell/g3 3779 firmware · dell/g3 15 3590 firmware · dell/g5 15 5590 firmware · dell/g5 5090 firmware · dell/g5 5587 firmware · dell/g7 15 7590 firmware · dell/g7 17 7790 firmware · dell/g7 7588 firmware · dell/inspiron 14 5490 firmware · dell/inspiron 3480 firmware · dell/inspiron 3481 firmware · dell/inspiron 3490 firmware · dell/inspiron 3493 firmware · dell/inspiron 3580 firmware · dell/inspiron 3581 firmware · dell/inspiron 3583 firmware · dell/inspiron 3584 firmware · dell/inspiron 3590 firmware · dell/inspiron 3593 firmware · +40 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.