CVE-2026-40639
Summary
| CVE | CVE-2026-40639 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-09 19:17:53 UTC |
| Updated | 2026-06-09 19:30:24 UTC |
| Description | Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
Risk And Classification
Primary CVSS: v3.1 5.7 MEDIUM from [email protected]
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS: 0.001190000 probability, percentile 0.021090000 (date 2026-06-16)
Problem Types: CWE-261 | CWE-261 CWE-261: Weak Encoding for Password
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.7 | MEDIUM | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 5.7 | MEDIUM | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
PhysicalAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Dell | Dell Edge Gateway 3000 | affected 1.26.0 semver | Not specified |
| CNA | Dell | Dell Edge Gateway 5000 | affected 1.36.0 semver | Not specified |
| CNA | Dell | DELL EMBEDDED PC 3000 | affected 1.32.0 semver | Not specified |
| CNA | Dell | DELL EMBEDDED PC 5000 | affected 1.33.0 semver | Not specified |
| CNA | Dell | Dell Precision 3630 Tower | affected 2.40.0 semver | Not specified |
| CNA | Dell | Dell Precision 3930 Rack | affected 2.43.0 semver | Not specified |
| CNA | Dell | Latitude 7220 Rugged Extreme | affected 1.51.0 semver | Not specified |
| CNA | Dell | Latitude Rugged 5420 | affected 1.42.0 semver | Not specified |
| CNA | Dell | Latitude Rugged 5424 | affected 1.42.0 semver | Not specified |
| CNA | Dell | Latitude Rugged 7220EX | affected 1.51.0 semver | Not specified |
| CNA | Dell | Latitude Rugged 7424 | affected 1.42.0 semver | Not specified |
| CNA | Dell | Precision 3930 Rack | affected 2.43.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.dell.com/support/kbdoc/en-us/000453482/dsa-2026-197 | [email protected] | www.dell.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Dell would like to thank Darren McDonald from AmberWolf and Craig S. Blackie from MDSec for reporting this issue. (en)
There are currently no legacy QID mappings associated with this CVE.