ID

VAR-202011-1262


CVE

CVE-2020-5388


TITLE

Dell Inspiron 15 7579 2-in-1 BIOS  Buffer Error Vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2020-013400

DESCRIPTION

Dell Inspiron 15 7579 2-in-1 BIOS versions prior to 1.31.0 contain an Improper SMM communication buffer verification vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. Dell Inspiron 15 7579 2-in-1 (Dell Inspiron) is a notebook computer of Dell (Dell) in the United States

Trust: 2.16

sources: NVD: CVE-2020-5388 // JVNDB: JVNDB-2020-013400 // CNVD: CNVD-2020-63984

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-63984

AFFECTED PRODUCTS

vendor:dellmodel:inspiron 15 7579scope:ltversion:1.31.0

Trust: 1.0

vendor:デルmodel:inspiron 15 7579scope:eqversion: -

Trust: 0.8

vendor:デルmodel:inspiron 15 7579scope:eqversion:inspiron 15 7579 firmware 1.31.0

Trust: 0.8

vendor:dellmodel:inspiron 2-in-1 <biosscope:eqversion:1575791.31.0

Trust: 0.6

sources: CNVD: CNVD-2020-63984 // JVNDB: JVNDB-2020-013400 // NVD: CVE-2020-5388

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-5388
value: MEDIUM

Trust: 1.0

security_alert@emc.com: CVE-2020-5388
value: MEDIUM

Trust: 1.0

NVD: CVE-2020-5388
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-63984
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202011-827
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-5388
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2020-63984
severity: MEDIUM
baseScore: 5.9
vectorString: AV:L/AC:H/AU:M/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: HIGH
authentication: MULTIPLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 1.2
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-5388
baseSeverity: MEDIUM
baseScore: 6.9
vectorString: CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
attackVector: PHYSICAL
attackComplexity: HIGH
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.3
impactScore: 6.0
version: 3.1

Trust: 2.0

OTHER: JVNDB-2020-013400
baseSeverity: MEDIUM
baseScore: 6.9
vectorString: CVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
attackVector: PHYSICAL
attackComplexity: HIGH
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-63984 // JVNDB: JVNDB-2020-013400 // CNNVD: CNNVD-202011-827 // NVD: CVE-2020-5388 // NVD: CVE-2020-5388

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.0

problemtype:Buffer error (CWE-119) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-013400 // NVD: CVE-2020-5388

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202011-827

PATCH

title:DSA-2020-215url:https://www.dell.com/support/article/en-us/sln322869/dsa-2020-215-dell-inspiron-15-7579-2-in-1-improper-smm-communication-buffer-boundary-verification-vulnerability

Trust: 0.8

title:Patch for Dell Inspiron buffer overflow vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/240232

Trust: 0.6

title:Dell Inspiron 15 7579 2-in-1 Buffer error vulnerability fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=134966

Trust: 0.6

sources: CNVD: CNVD-2020-63984 // JVNDB: JVNDB-2020-013400 // CNNVD: CNNVD-202011-827

EXTERNAL IDS

db:NVDid:CVE-2020-5388

Trust: 3.0

db:JVNDBid:JVNDB-2020-013400

Trust: 0.8

db:CNVDid:CNVD-2020-63984

Trust: 0.6

db:CNNVDid:CNNVD-202011-827

Trust: 0.6

sources: CNVD: CNVD-2020-63984 // JVNDB: JVNDB-2020-013400 // CNNVD: CNNVD-202011-827 // NVD: CVE-2020-5388

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-5388

Trust: 2.0

url:https://www.dell.com/support/article/en-us/sln322869/dsa-2020-215-dell-inspiron-15-7579-2-in-1-improper-smm-communication-buffer-boundary-verification-vulnerability

Trust: 1.6

sources: CNVD: CNVD-2020-63984 // JVNDB: JVNDB-2020-013400 // CNNVD: CNNVD-202011-827 // NVD: CVE-2020-5388

SOURCES

db:CNVDid:CNVD-2020-63984
db:JVNDBid:JVNDB-2020-013400
db:CNNVDid:CNNVD-202011-827
db:NVDid:CVE-2020-5388

LAST UPDATE DATE

2024-11-23T22:25:15.173000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-63984date:2020-11-18T00:00:00
db:JVNDBid:JVNDB-2020-013400date:2021-06-30T08:35:00
db:CNNVDid:CNNVD-202011-827date:2020-11-27T00:00:00
db:NVDid:CVE-2020-5388date:2024-11-21T05:34:02.710

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-63984date:2020-11-18T00:00:00
db:JVNDBid:JVNDB-2020-013400date:2021-06-30T00:00:00
db:CNNVDid:CNNVD-202011-827date:2020-11-10T00:00:00
db:NVDid:CVE-2020-5388date:2020-11-10T15:15:12.657