CVE-2020-5363

HIGH

Dell Client Consumer/Commercial - Privilege Escalation

Title source: llm
STIX 2.1

Description

Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially allow an unauthorized actor, with physical access and/or OS administrator privileges to the device, to gain privileged access to the platform and the hard drive.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.dell.com/support/article/SLN321604

Scores

CVSS v3 8.6
EPSS 0.0005
EPSS Percentile 15.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-158
Status published
Products (18)
dell/latitude_5300_2-in-1_firmware < 1.9.4
dell/latitude_5300_firmware < 1.9.4
dell/latitude_5400_firmware < 1.7.4
dell/latitude_5401_firmware < 1.8.4
dell/latitude_5500_firmware < 1.7.4
dell/latitude_5501_firmware < 1.8.4
dell/latitude_7200_2_in_1_firmware < 1.8.0
dell/latitude_7220_firmware < 1.6.0
dell/latitude_7220ex_rugged_extreme_tablet_firmware < 1.6.0
dell/latitude_7300_firmware < 1.7.4
... and 8 more
Published Jun 10, 2020
Tracked Since Feb 18, 2026