First published: Mon Dec 16 2019(Updated: )
Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for the "Enable Thunderbolt (and PCIe behind TBT) pre-boot modules" setting is enabled by default. A local unauthenticated attacker with physical access to a user's system can obtain read or write access to main memory via a DMA attack during platform boot.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell XPS 13 7390 Firmware | <1.1.3 | |
Dell XPS 7390 2-in-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-18579 is considered medium due to the potential for unauthorized access via a physical attack.
To fix CVE-2019-18579, update the Dell XPS 13 7390 firmware to version 1.1.3 or later.
CVE-2019-18579 affects Dell XPS 13 2-in-1 devices with BIOS versions prior to 1.1.3.
CVE-2019-18579 is a configuration vulnerability that allows local unauthorized access to BIOS settings.
CVE-2019-18579 can be exploited by a local unauthenticated attacker with physical access to the device.