CVE-2020-5326
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu.
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring the BIOS Admin password by selecting the Optimized Defaults option in the pre-boot iRST Manager.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- dell/chengming 3980 firmware · dell/g3 3579 firmware · dell/g3 3590 firmware · dell/g3 3779 firmware · dell/g5 5587 firmware · dell/g5 5590 firmware · dell/g7 7588 firmware · dell/g7 7590 firmware · dell/g7 7790 firmware · dell/embedded box pc 5000 firmware · dell/inspiron 14 gaming 7466 firmware · dell/inspiron 14 gaming 7467 firmware · dell/inspiron 15 7572 firmware · dell/inspiron 15 gaming 7566 firmware · dell/inspiron 15 gaming 7567 firmware · dell/inspiron 15 gaming 7577 firmware · dell/inspiron 3470 firmware · dell/inspiron 3480 firmware · dell/inspiron 3481 firmware · dell/inspiron 3580 firmware · +40 more
- Source
- security_alert@emc.com
References
- https://www.dell.com/support/article/SLN320337Vendor Advisory
- https://www.dell.com/support/article/SLN320337Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.