PT-2021-12399 · Dell · Dell Client Commercial+1
Published
2021-01-04
·
Updated
2021-01-29
·
CVE-2020-5361
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dell Client Commercial and Consumer platforms (affected versions not specified)
Description
The issue concerns unauthorized password generation tools that can reset BIOS passwords and BIOS-managed Hard Disk Drive (HDD) passwords. An unauthenticated attacker with physical access to the system could exploit this to bypass security restrictions for BIOS Setup configuration, HDD access, and BIOS pre-boot authentication.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Client Commercial
Dell Client Consumer