CVE-2026-40639
Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.7
- CVSS vector
- CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.19%
- CWE
- CWE-261
- Published
- 2026-06-09
- Last modified
- 2026-06-09
Affected products
- Dell Dell Edge Gateway 3000
- Dell Dell Edge Gateway 5000
- Dell DELL EMBEDDED PC 3000
- Dell DELL EMBEDDED PC 5000
- Dell Dell Precision 3630 Tower
- Dell Dell Precision 3930 Rack
- Dell Latitude 7220 Rugged Extreme
- Dell Latitude Rugged 5420
Weakness type
Related vulnerabilities
- CVE-2026-63424 — During an internal security assessment, an improperly protected key was discovered in Lenovo Dock...
- CVE-2026-67596 — CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg
- CVE-2026-53692 — Weak hashing algorithm in Redeight CMS
- CVE-2026-25607 — Weak password encoding in STER
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2026-0809 — Weak KSeF token encoding in Streamsoft Prestiż
- CVE-2024-52334 — A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected...
- CVE-2025-67652 — AutomationDirect CLICK Programmable Logic Controller Weak Encoding for Password