Improper Authorization in Dell Manageability Interface for Consumer and Commercial Platforms
CVE-2020-5362
7.1HIGH
Key Information:
- Vendor
Dell
- Vendor
- CVE Published:
- 10 June 2020
What is CVE-2020-5362?
In the Dell Manageability interface for both Consumer and Commercial platforms, an improper authorization vulnerability has been identified. This flaw permits an unauthorized actor with local system access and OS administrator privileges to bypass the BIOS Administrator authentication. Consequently, this allows the attacker to restore the BIOS Setup configuration to default values, potentially exposing sensitive settings or altering system behavior.
Affected Version(s)
Dell Client Consumer and Commercial platforms https://www.dell.com/support/article/SLN321726