CVE-2025-29989

MEDIUM EPSS 2.0%
Published Apr 10, 20251y ago · Modified Jun 17, 20261w ago
4.4 CVSS 3.1
Medium
Find Similar
Published Apr 10, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.

CVSS Details

Base Score
4.4
Exploitability
0.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.0% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-1328

Affected Products 8

VendorProductVersionRange
dellprecision_5820_tower_firmware* <2.42.0
dellprecision_5820_tower*any
dellprecision_7820_tower_firmware* <2.46.0
dellprecision_7820_tower*any
dellprecision_7920_tower_firmware* <2.46.0
dellprecision_7920_tower*any
dellprecision_7865_tower_firmware* <1.18.0
dellprecision_7865_tower*any

References 1

  • dell.com https://www.dell.com/support/kbdoc/en-us/000250131/dsa-2025-016
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.