CVE-2019-3717Dell Chengming 3967 Firmware vulnerability

3 documents3 sources
Severity
6.8MEDIUMNVD
EPSS
0.1%
top 79.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5
Latest updateMay 24

Description

Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages240 packages

CVEListV5dell/dell_client_commercial_and_consumer_platformshttps://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en
NVDdell/g5_5587_firmware< 1.10.0

🔴Vulnerability Details

2
GHSA
GHSA-72vg-39jq-h2mg: Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability2022-05-24
CVEList
CVE-2019-3717: Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability2019-08-05
CVE-2019-3717 — Dell vulnerability | cvebase