Start a Conversation

Unsolved

K

1 Rookie

 • 

65 Posts

669

June 27th, 2021 17:00

Dell Bios Connect

I saw multiple articles regarding this. Not sure if you can post a link to them or not, but here is the title of one of them

ECLYPSIUM DISCOVERS MULTIPLE VULNERABILITIES AFFECTING 129 DELL MODELS VIA DELL REMOTE OS RECOVERY AND FIRMWARE UPDATE CAPABILITIES

I know that Dell Support Assistant uses this. Not sure about Dell Update.

So if you don't have Dell SupportAssistant installed, do you need to worry about this? And what about Dell Upate?

I don't have SupportAssistant installed but I do have Dell Update installed. But I'm thinking of un-installing it because it keeps wanting me to install the same update every 2 days even though it says it was successful all the times that I did install it. This update was for Dell Update itself. It's funny. There are two updates listed for this app in my account for my pc. The first one says it is for THIS PC. The second one says something about Alienware. And that is the one it keeps wanting to install. I have an XPS8920.

So the question is this: Do I need to patch anything for this vulnerability or not?

9 Legend

 • 

47K Posts

June 27th, 2021 20:00

Exploiting the chain requires additional steps:

  • To exploit the vulnerability chain in BIOSConnect, a malicious actor must separately perform additional steps before a successful exploit, including: compromise a user’s network, obtain a certificate that is trusted by one of the Dell UEFI BIOS https stack’s built-in Certificate Authorities, and wait for a user who is physically present at the system to use the BIOSConnect feature.

 

  • To exploit the vulnerability in HTTPS Boot, a malicious actor must separately perform additional steps before a successful exploit, including: compromise a user’s network, obtain a certificate that is trusted by one of the Dell UEFI BIOS https stack’s built-in Certificate Authorities, and wait for a user who is physically present at the system to change the boot order and use the HTTPS Boot feature.
No Events found!

Top