Dell Client Consumer and Commercial platforms contain remediation for a BIOS Password Recovery Mechanism vulnerability that could be exploited by malicious users to compromise the affected systems.
Summary:Dell Client Consumer and Commercial platforms contain remediation for a BIOS Password Recovery Mechanism vulnerability that could be exploited by malicious users to compromise the affected systems.See lessDell Client Consumer and Commercial platforms contain remediation for a BIOS Password Recovery Mechanism vulnerability that could be exploited by malicious users to compromise theSee more
Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. Dell is aware of unauthorized password generation tools that can generate BIOS recovery passwords. The tools, which are not authorized by Dell, can be used by a physically present attacker to reset BIOS passwords and BIOS-managed Hard Disk Drive (HDD) passwords. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to bypass security restrictions for BIOS Setup configuration, HDD access and BIOS pre-boot authentication.
CVSS Base Score: 5.1 (AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L)
Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. Dell is aware of unauthorized password generation tools that can generate BIOS recovery passwords. The tools, which are not authorized by Dell, can be used by a physically present attacker to reset BIOS passwords and BIOS-managed Hard Disk Drive (HDD) passwords. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to bypass security restrictions for BIOS Setup configuration, HDD access and BIOS pre-boot authentication.
CVSS Base Score: 5.1 (AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L)
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
Affected Products and Remediation
Customers can choose to enable the Master Password Lockout feature from BIOS Setup (available on commercial platforms starting from 2011) to protect BIOS Admin, BIOS System and HDD passwords from being reset. Dell also recommends customers follow security best practices and prevent unauthorized physical access to devices.
Warning: If the Master Password Lockout option is selected and the customer subsequently forgets the password, Dell will not be able to assist in the recovery of passwords. The platform will be unrecoverable, and the motherboard or hard drive will need to be replaced.
Dell Client Consumer and Commercial Platforms Affected This issue affects select Dell Client Commercial and Consumer systems. Any platform that displays the following identifiers on the BIOS pre-boot password prompts (Dell Security Manager) are impacted.
<SERVICE TAG or HDD SN>-D35B
<SERVICE TAG or HDD SN>-1F5A
<SERVICE TAG or HDD SN>-595B
<SERVICE TAG or HDD SN>-2A7B
<SERVICE TAG or HDD SN>-1D3B
<SERVICE TAG or HDD SN>-1F66
<SERVICE TAG or HDD SN>-6FF1
<SERVICE TAG or HDD SN>-BF97
Customers can choose to enable the Master Password Lockout feature from BIOS Setup (available on commercial platforms starting from 2011) to protect BIOS Admin, BIOS System and HDD passwords from being reset. Dell also recommends customers follow security best practices and prevent unauthorized physical access to devices.
Warning: If the Master Password Lockout option is selected and the customer subsequently forgets the password, Dell will not be able to assist in the recovery of passwords. The platform will be unrecoverable, and the motherboard or hard drive will need to be replaced.
Dell Client Consumer and Commercial Platforms Affected This issue affects select Dell Client Commercial and Consumer systems. Any platform that displays the following identifiers on the BIOS pre-boot password prompts (Dell Security Manager) are impacted.
The information in this Dell Technologies Security Advisory should be read and used to assist in avoiding situations that may arise from the problems described herein. Dell Technologies distributes Security Advisories to bring important security information to the attention of users of the affected product(s). Dell Technologies assesses the risk based on an average of risks across a diverse set of installed systems and may not represent the actual risk to your local installation and individual environment. It is recommended that all users determine the applicability of this information to their individual environments and take appropriate actions. The information set forth herein is provided "as is" without warranty of any kind. Dell Technologies expressly disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall Dell Technologies, its affiliates or suppliers, be liable for any damages whatsoever arising from or related to the information contained herein or actions that you decide to take based thereon, including any direct, indirect, incidental, consequential, loss of business profits or special damages, even if Dell Technologies, its affiliates or suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation shall apply to the extent permissible under law.
Article Properties
Affected Product
Product Security Information
Last Published Date
17 Dec 2020
Version
3
Article Type
Dell Security Advisory
Rate This Article
Thank you for your feedback.
Sorry, our feedback system is currently down. Please try again later.
Comments cannot contain these special characters: <>()\