文章編號: 000180645
Medium
Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
CVE-2020-26186 | Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the RuntimeServices structure to execute arbitrary code in System Management Mode (SMM). |
6.8 | CVSS:3.1:AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
CVE-2020-26186 | Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the RuntimeServices structure to execute arbitrary code in System Management Mode (SMM). |
6.8 | CVSS:3.1:AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Dell Technologies 建議所有客戶不僅要參考 CVSS 基本分數,也要將可能會影響與特定安全漏洞相關之潛在嚴重性的所有相關暫時和環境分數納入考量。
Product | Update BIOS Version (or greater) |
Release Date (MM/DD/YYYY) Expected Release (Month/YYYY) |
Dell Inspiron 5675 | 1.4.1 | 11/18/2020 |
Product | Update BIOS Version (or greater) |
Release Date (MM/DD/YYYY) Expected Release (Month/YYYY) |
Dell Inspiron 5675 | 1.4.1 | 11/18/2020 |
None
Dell would like to thank yngweijw for reporting this vulnerability.
Revision | Date | Description |
1.0 | 12/15/2020 | Initial Release |
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide
請務必閱讀並使用此 Dell Technologies 安全性公告中的資訊,以協助避免此處所述問題可能造成的情況。Dell Technologies 會發佈安全性公告,讓受影響產品的使用者留意重要的安全性資訊。Dell Technologies 是依據各種已安裝系統的平均風險來評估風險,不一定能代表本機安裝和個別環境的實際風險。建議所有使用者確定此資訊對其個別環境的適用性,並採取適當行動。此處列出的資訊「依現況」提供,不含任何形式的保固。Dell Technologies 明確表示不提供任何明示或暗示的擔保,包括適銷性、特定用途的適用性、所有權及非侵權的擔保。在任何情況下,對於因本文所含資訊或您決定據此採取行動所造成或與之相關的任何損害,Dell Technologies、其關係企業或供應商概不負責,包括直接、間接、附帶、衍生性、業務利潤損失或特殊損害,即使 Dell Technologies、其關係企業或供應商對上述損害的可能性已經知情亦然。部分州別不允許排除或限制衍生性或附帶損害的責任,因此上述限制應在法律允許的範圍內適用。
Inspiron 5675
15 12月 2020
1
Dell Security Advisory