Dell Client BIOS Weak Encoding Password EE Privilege Escalation
CVE-2026-40639 Published on June 9, 2026
Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Vulnerability Analysis
CVE-2026-40639 can be exploited with physical access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Weak Encoding for Password
Obscuring a password with a trivial encoding does not protect the password. Password management issues occur when a password is stored in plaintext in an application's properties or configuration file. A programmer can attempt to remedy the password management problem by obscuring the password with an encoding function, such as base 64 encoding, but this effort does not adequately protect the password.
Affected Versions
Dell Edge Gateway 3000:- Before 1.26.0 is affected.
- Before 1.36.0 is affected.
- Before 1.32.0 is affected.
- Before 1.33.0 is affected.
- Before 2.40.0 is affected.
- Before 2.43.0 is affected.
- Before 1.51.0 is affected.
- Before 1.42.0 is affected.
- Before 1.42.0 is affected.
- Before 1.51.0 is affected.
- Before 1.42.0 is affected.
- Before 2.43.0 is affected.