CVE-2026-40639

Die Dell Client-Plattform-BIOS enthält eine Schwachstelle aufgrund schwacher Passwortkodierung.

mediumEPSS 0.2%

Description

Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.

Metrics

5.7
Source: nvd-v3
5.5 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-06-09 18:04 UTC
CWE-261

Weakness classes (CWE)

  • CWE-261Base

    Weak Encoding for Password

    Obscuring a password with a trivial encoding does not protect the password.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-23 09:10 UTC· nvd@nist.gov
    • Translation: Title: varios productor Dell, Description: Dell Client Platform BIOS contiene una vulnerabilidad de codificación débil para contraseñas. Un atacante no autenticado con acceso físico podría potencialmente explotar esta vulnerabilidad, lo que podría llevar a una Elevación de Privilegios.

Linked advisories