CVE-2019-3717

MEDIUM

Dell Client Commercial and Consumer - Privilege Escalation

Title source: llm
STIX 2.1

Description

Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.

Scores

CVSS v3 6.8
EPSS 0.0007
EPSS Percentile 20.6%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (50)
dell/chengming_3967_firmware < 1.5.0
dell/chengming_3977_firmware < 1.6.0
dell/chengming_3980_firmware < 1.5.21
dell/embedded_box_pc_5000_firmware < 1.5.6
dell/g3_3579_firmware < 1.9.0
dell/g3_3779_firmware < 1.9.0
dell/g5_5587_firmware < 1.10.0
dell/g5_5590_firmware < 1.3.1
dell/g7_7588_firmware < 1.10.0
dell/g7_7590_firmware < 1.3.1
... and 40 more
Published Aug 05, 2019
Tracked Since Feb 18, 2026