BIOS Setup Configuration Authentication Bypass in Dell Client Platforms
CVE-2020-5326

6.1MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
21 February 2020

Summary

Dell Client platforms are affected by a vulnerability that allows an attacker with physical access to modify BIOS Setup configuration settings without the need for the BIOS Admin password. This is achieved through an exploit in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu, where selecting the Optimized Defaults option grants unauthorized access to critical configuration settings.

Affected Version(s)

Dell Client Consumer and Commercial Platforms https://www.dell.com/support/article/SLN320337

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.