Junglewise Threat Intelligence

CVE-2026-40639: Dell Client Platform BIOS weak password encoding

CVE-2026-40639 · Severity: medium · CVSS 5.7 · Published 2026-06-09

Vendors: Dell.

Executive brief

A security vulnerability exists in the BIOS firmware of several Dell client platforms, including certain Latitude, Precision, and Edge Gateway models. The BIOS is the fundamental software that starts a computer and manages hardware settings. An attacker with physical access to the device could bypass password protections, potentially gaining unauthorized control over the system's configuration and elevating their privileges.

Technical details

A Weak Encoding for Password vulnerability (CWE-261) exists in the BIOS of multiple Dell client platforms. The flaw resides in how passwords are encoded or stored within the firmware, making them susceptible to recovery or bypass. An unauthenticated attacker requires physical access to the target machine to exploit this issue. Successful exploitation allows for elevation of privileges, potentially granting the attacker control over BIOS settings and the boot process. Dell has released firmware updates for affected models to remediate the vulnerability.

Affected products

  • Dell Edge Gateway 3000 BIOS prior to 1.26.0
  • Dell Edge Gateway 5000 BIOS prior to 1.36.0
  • Dell Embedded PC 3000 BIOS prior to 1.32.0
  • Dell Embedded PC 5000 BIOS prior to 1.33.0
  • Dell Precision 3630 Tower BIOS prior to 2.40.0
  • Dell Precision 3930 Rack BIOS prior to 2.43.0
  • Dell Latitude 7220 Rugged Extreme BIOS prior to 1.51.0
  • Dell Latitude Rugged 5420 BIOS prior to 1.42.0

Timeline

  • 2026-06-09: disclosed: Initial release of DSA-2026-197
  • 2026-06-09: patched: Remediated BIOS versions released for affected platforms

References