Home

Description

Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.

PUBLISHED Reserved 2026-04-14 | Published 2026-06-09 | Updated 2026-06-09 | Assigner dell




MEDIUM: 5.7CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Problem types

CWE-261: Weak Encoding for Password

Product status

Default status
unaffected

Any version before 1.26.0
affected

Default status
unaffected

Any version before 1.36.0
affected

Default status
unaffected

Any version before 1.32.0
affected

Default status
unaffected

Any version before 1.33.0
affected

Default status
unaffected

Any version before 2.40.0
affected

Default status
unaffected

Any version before 2.43.0
affected

Default status
unaffected

Any version before 1.51.0
affected

Default status
unaffected

Any version before 1.42.0
affected

Default status
unaffected

Any version before 1.42.0
affected

Default status
unaffected

Any version before 1.51.0
affected

Default status
unaffected

Any version before 1.42.0
affected

Default status
unaffected

Any version before 2.43.0
affected

Credits

Dell would like to thank Darren McDonald from AmberWolf and Craig S. Blackie from MDSec for reporting this issue. finder

References

www.dell.com/support/kbdoc/en-us/000453482/dsa-2026-197 vendor-advisory

cve.org (CVE-2026-40639)

nvd.nist.gov (CVE-2026-40639)

Download JSON