CVE-2019-18579: High severity dell xps 13 7390 firmware vulnerability
Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for the "Enable Thunderbolt (and PCIe behind TBT) pre-boot modules" setting is enabled by default. A local unauthenticated attacker with physical access to a user's system can obtain read or write access to main memory via a DMA attack during platform boot.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18579?
The severity of CVE-2019-18579 is considered medium due to the potential for unauthorized access via a physical attack.
How do I fix CVE-2019-18579?
To fix CVE-2019-18579, update the Dell XPS 13 7390 firmware to version 1.1.3 or later.
What systems are affected by CVE-2019-18579?
CVE-2019-18579 affects Dell XPS 13 2-in-1 devices with BIOS versions prior to 1.1.3.
What kind of vulnerability is CVE-2019-18579?
CVE-2019-18579 is a configuration vulnerability that allows local unauthorized access to BIOS settings.
Who can exploit CVE-2019-18579?
CVE-2019-18579 can be exploited by a local unauthenticated attacker with physical access to the device.