CVE-2025-36579

MEDIUM

Dell Pro 14 Essential PV14250 <1.4.0 - Weak Password Recovery

Title source: llm
STIX 2.1

Description

Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.

Scores

CVSS v3 5.1
EPSS 0.0001
EPSS Percentile 1.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-640
Status published
Products (50)
Dell/Alienware 16 Area-51 AA16250 < 1.9.0
Dell/Alienware 16X Aurora AC16251 < 1.8.1
Dell/Alienware 18 Area-51 AA18250 < 1.9.0
Dell/Alienware Area-51 AAT225 < 1.11.0
Dell/Alienware Aurora ACT1250 < 1.10.0
Dell/Alienware m15 R6 < 1.42.0
Dell/Alienware m15 R7 < 1.37.0
Dell/Alienware m16 R1 < 1.32.0
Dell/Alienware m16 R2 < 1.18.0
Dell/Alienware m18 R1 < 1.32.0
... and 40 more
Published Apr 16, 2026
Tracked Since Apr 16, 2026