CVE-2019-18579

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/12/2019
Last modified:
30/12/2019

Description

Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for the "Enable Thunderbolt (and PCIe behind TBT) pre-boot modules" setting is enabled by default. A local unauthenticated attacker with physical access to a user's system can obtain read or write access to main memory via a DMA attack during platform boot.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:xps_7390_firmware:*:*:*:*:*:*:*:* 1.1.3 (excluding)
cpe:2.3:h:dell:xps_7390:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools