Unauthorized BIOS Admin Password Modification in Dell Client Platforms
CVE-2020-5363
8.6HIGH
Key Information:
- Vendor
Dell
- Vendor
- CVE Published:
- 10 June 2020
What is CVE-2020-5363?
Certain Dell Client Consumer and Commercial platforms have a vulnerability that enables the BIOS Admin password to be altered via Dell's manageability interface without needing the current password. This flaw poses a significant risk, allowing individuals with physical access and/or OS administrator privileges to compromise the platform, gaining elevated access to the system, including sensitive data stored on the hard drive.
Affected Version(s)
Dell Client Consumer and Commercial platforms https://www.dell.com/support/article/SLN321604