CVE-2020-5363
Summary
| CVE | CVE-2020-5363 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-10 21:15:00 UTC |
| Updated | 2020-06-23 16:16:00 UTC |
| Description | Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially allow an unauthorized actor, with physical access and/or OS administrator privileges to the device, to gain privileged access to the platform and the hard drive. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dell | Latitude 5300 | - | All | All | All |
| Hardware | Dell | Latitude 5300 | - | All | All | All |
| Hardware | Dell | Latitude 5300 2-in-1 | - | All | All | All |
| Hardware | Dell | Latitude 5300 2-in-1 | - | All | All | All |
| Operating System | Dell | Latitude 5300 2-in-1 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 5300 2-in-1 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 5300 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 5300 Firmware | All | All | All | All |
| Hardware | Dell | Latitude 5400 | - | All | All | All |
| Hardware | Dell | Latitude 5400 | - | All | All | All |
| Operating System | Dell | Latitude 5400 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 5400 Firmware | All | All | All | All |
| Hardware | Dell | Latitude 5401 | - | All | All | All |
| Hardware | Dell | Latitude 5401 | - | All | All | All |
| Operating System | Dell | Latitude 5401 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 5401 Firmware | All | All | All | All |
| Hardware | Dell | Latitude 5500 | - | All | All | All |
| Hardware | Dell | Latitude 5500 | - | All | All | All |
| Operating System | Dell | Latitude 5500 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 5500 Firmware | All | All | All | All |
| Hardware | Dell | Latitude 5501 | - | All | All | All |
| Hardware | Dell | Latitude 5501 | - | All | All | All |
| Operating System | Dell | Latitude 5501 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 5501 Firmware | All | All | All | All |
| Hardware | Dell | Latitude 7200 2 In 1 | - | All | All | All |
| Hardware | Dell | Latitude 7200 2 In 1 | - | All | All | All |
| Operating System | Dell | Latitude 7200 2 In 1 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 7200 2 In 1 Firmware | All | All | All | All |
| Hardware | Dell | Latitude 7220 | - | All | All | All |
| Hardware | Dell | Latitude 7220 | - | All | All | All |
| Hardware | Dell | Latitude 7220ex Rugged Extreme Tablet | - | All | All | All |
| Hardware | Dell | Latitude 7220ex Rugged Extreme Tablet | - | All | All | All |
| Operating System | Dell | Latitude 7220ex Rugged Extreme Tablet Firmware | All | All | All | All |
| Operating System | Dell | Latitude 7220ex Rugged Extreme Tablet Firmware | All | All | All | All |
| Operating System | Dell | Latitude 7220 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 7220 Firmware | All | All | All | All |
| Hardware | Dell | Latitude 7300 | - | All | All | All |
| Hardware | Dell | Latitude 7300 | - | All | All | All |
| Operating System | Dell | Latitude 7300 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 7300 Firmware | All | All | All | All |
| Hardware | Dell | Latitude 7400 | - | All | All | All |
| Hardware | Dell | Latitude 7400 | - | All | All | All |
| Operating System | Dell | Latitude 7400 Firmware | All | All | All | All |
| Operating System | Dell | Latitude 7400 Firmware | All | All | All | All |
| Hardware | Dell | Precision 3540 | - | All | All | All |
| Hardware | Dell | Precision 3540 | - | All | All | All |
| Operating System | Dell | Precision 3540 Firmware | All | All | All | All |
| Operating System | Dell | Precision 3540 Firmware | All | All | All | All |
| Hardware | Dell | Precision 3541 | - | All | All | All |
| Hardware | Dell | Precision 3541 | - | All | All | All |
| Operating System | Dell | Precision 3541 Firmware | All | All | All | All |
| Operating System | Dell | Precision 3541 Firmware | All | All | All | All |
| Hardware | Dell | Precision 7540 | - | All | All | All |
| Hardware | Dell | Precision 7540 | - | All | All | All |
| Operating System | Dell | Precision 7540 Firmware | All | All | All | All |
| Operating System | Dell | Precision 7540 Firmware | All | All | All | All |
| Hardware | Dell | Precision 7740 | - | All | All | All |
| Hardware | Dell | Precision 7740 | - | All | All | All |
| Operating System | Dell | Precision 7740 Firmware | All | All | All | All |
| Operating System | Dell | Precision 7740 Firmware | All | All | All | All |
| Hardware | Dell | Xps 13 9300 | - | All | All | All |
| Hardware | Dell | Xps 13 9300 | - | All | All | All |
| Operating System | Dell | Xps 13 9300 Firmware | All | All | All | All |
| Operating System | Dell | Xps 13 9300 Firmware | All | All | All | All |
| Hardware | Dell | Xps 7390 2-in-1 | - | All | All | All |
| Hardware | Dell | Xps 7390 2-in-1 | - | All | All | All |
| Operating System | Dell | Xps 7390 2-in-1 Firmware | All | All | All | All |
| Operating System | Dell | Xps 7390 2-in-1 Firmware | All | All | All | All |
| Hardware | Dell | Xps 7590 | - | All | All | All |
| Hardware | Dell | Xps 7590 | - | All | All | All |
| Operating System | Dell | Xps 7590 Firmware | All | All | All | All |
| Operating System | Dell | Xps 7590 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DSA-2020-121: Dell Client Platform Security Update for BIOS Admin Password Change Verification Bypass Vulnerability | Dell US | MISC | www.dell.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.