PT-2021-12399 · Dell · Dell Client Commercial+1

Published

2021-01-04

·

Updated

2021-01-29

·

CVE-2020-5361

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell Client Commercial and Consumer platforms (affected versions not specified)
Description The issue concerns unauthorized password generation tools that can reset BIOS passwords and BIOS-managed Hard Disk Drive (HDD) passwords. An unauthenticated attacker with physical access to the system could exploit this to bypass security restrictions for BIOS Setup configuration, HDD access, and BIOS pre-boot authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5361

Affected Products

Dell Client Commercial
Dell Client Consumer