Search/CVE-2020-5362
CVE — High

CVE-2020-5362

Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.

CVSS v3.1
7.1 HIGH
EPSS
0.29%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 7, 2026
0.00pp
0.29% → 0.29% over 2 tracked changes
CVSS v3.1 Detail
Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeCHANGED
ConfidentialityLOW
IntegrityNONE
AvailabilityHIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:H
Connections
26 relationships
Timeline
disclosure → media coverage
Jun 10, 2020
Disclosure — published as a CVE record. · last revised by NVD Nov 21, 2024