CVE-2025-36579: CWE-640: Weak Password Recovery Mechanism for Forgotten Password in Dell Dell Pro 14 Essential PV14250
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.
AI Analysis
Technical Summary
This vulnerability affects the BIOS password recovery mechanism on the Dell Pro 14 Essential PV14250 platform. The weakness in the recovery process could be exploited by an attacker who has physical access to the device, enabling unauthorized access without authentication. The CVSS 3.1 vector indicates the attack requires physical access (AV:P), has low attack complexity (AC:L), requires no privileges (PR:N), no user interaction (UI:N), and impacts confidentiality, integrity, and availability to a limited extent (C:L/I:L/A:L). No patch or official remediation level has been published by Dell as of the data provided.
Potential Impact
An attacker with physical access to the affected Dell system could exploit the weak password recovery mechanism to bypass authentication controls, potentially gaining unauthorized access to the BIOS or system settings. This could lead to limited confidentiality, integrity, and availability impacts as indicated by the CVSS score. Remote exploitation is not possible due to the physical access requirement. No known exploits have been reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, physical security controls should be enforced to prevent unauthorized physical access to affected devices. Monitor Dell's advisories for updates on patches or mitigations.
CVE-2025-36579: CWE-640: Weak Password Recovery Mechanism for Forgotten Password in Dell Dell Pro 14 Essential PV14250
Description
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.
CVSS v3.1
Score 5.1medium
Affected software
Dell
Dell Pro 14 Essential PV14250
Dell
Dell Pro Micro / QCM1255
Dell
Dell Pro Slim / QCS1255
Dell
Dell Pro Tower / QCT1255
Dell
Alienware 16 Area-51 AA16250
Dell
Alienware 16X Aurora AC16251
Dell
Alienware 18 Area-51 AA18250
Dell
Alienware Area-51 AAT225
Dell
Alienware Aurora ACT1250
Dell
Alienware m15 R6
Dell
Alienware m15 R7
Dell
Alienware m16 R1
Dell
Alienware m16 R2
Dell
Alienware m18 R1
Dell
Alienware M18 R2
Dell
Alienware x14 R2
Dell
Alienware x16 R1
Dell
Alienware X16 R2
Dell
ChengMing 3900
Dell
ChengMing 3910/3911
Dell
ChengMing 3990
Dell
ChengMing 3991
Dell
Dell 14 DC14250
Dell
Dell 14 Premium DA14250
Dell
Dell 15 DC15250
Dell
Dell 16 DC16250
Dell
Dell 16 DC16251
Dell
Dell 16 Premium DA16250
Dell
Dell G15 5510
Dell
Dell G15 5511
Dell
Dell G15 5520
Dell
Dell G15 5530
Dell
Dell G16 7620
Dell
Dell G16 7630
Dell
Dell G5 5000
Dell
Dell Pro 13 Plus PB13250
Dell
Dell Pro 13 Plus PB13255
Dell
Dell Pro 13 Premium PA13250
Dell
Dell Pro 14 PC14250
Dell
Dell Pro 14 Plus PB14250
Dell
Dell Pro 14 Plus PB14255
Dell
Dell Pro 14 Premium PA14250
Dell
Dell Pro 15 Essential PV15250
Dell
Dell Pro 16 PC16250
Dell
Dell Pro 16 Plus PB16250
Dell
Dell Pro 16 Plus PB16255
Dell
Dell Pro 24 All-in-One Plus/Dell Pro 24 All-in-One
Dell
Dell Pro Laptop PC14250
Dell
Dell Pro Laptop PC16250
Dell
Dell Pro Max 14 MC14250
Dell
Dell Pro Max 14 MC14255
Dell
Dell Pro Max 16 MC16250
Dell
Dell Pro Max 16 MC16255
Dell
Dell Pro Max Micro FCM2250
Dell
Dell Pro Max Slim FCS1250
Dell
Dell Pro Max Tower T2 FCT2250
Dell
Dell Pro Micro/Micro Plus QCM1250/QBM1250
Dell
Dell Pro Rugged 13 RA13250
Dell
Dell Pro Rugged 14 RB14250
Dell
Dell Pro Slim Essential QVS1260
Dell
Dell Pro Slim Plus QBS1250/Dell Pro Slim QCS1250
Dell
Dell Pro Tower Essential QVT1260
Dell
Dell Pro Tower Plus QBT1250/Dell Pro Tower QCT1250
Dell
Dell Slim ECS1250
Dell
Dell Tower ECT1250
Dell
Dell Tower Plus EBT2250
Dell
Inspiron 13 5320
Dell
Inspiron 13 5330
Dell
Inspiron 14 5420
Dell
Inspiron 14 5430
Dell
Inspiron 14 5440
Dell
Inspiron 14 7420 2-in-1
Dell
Inspiron 14 7430 2-in-1
Dell
Inspiron 14 7440 2-in-1
Dell
Inspiron 14 Plus 7420
Dell
Inspiron 14 Plus 7430
Dell
Inspiron 14 Plus 7440
Dell
Inspiron 15 3511
Dell
Inspiron 15 3520
Dell
Inspiron 16 5620
Dell
Inspiron 16 5630
Dell
Inspiron 16 5640
Dell
Inspiron 16 7610
Dell
Inspiron 16 7620 2-in-1
Dell
Inspiron 16 7630 2-in-1
Dell
Inspiron 16 7640 2-in-1
Dell
Inspiron 16 Plus 7620
Dell
Inspiron 16 Plus 7630
Dell
Inspiron 16 Plus 7640
Dell
Inspiron 24 5420 All-in-One
Dell
Inspiron 24 5430 All-in-One
Dell
Inspiron 27 7720 All-in-One
Dell
Inspiron 27 7730 All-in-One
Dell
Inspiron 3020 Desktop
Dell
Inspiron 3020 Small Desktop
Dell
Inspiron 3030
Dell
Inspiron 3030S
Dell
Inspiron 3910
Dell
Inspiron 5400/5401
Dell
Inspiron 5401 AIO
Dell
Inspiron 5410 All-in-One
Dell
Inspiron 5510
Dell
Inspiron 7700 All-In-One
Dell
Inspiron 7710 All-in-One
Dell
Latitude 3120
Dell
Latitude 3140
Dell
Latitude 3140 2in1
Dell
Latitude 3320
Dell
Latitude 3330
Dell
Latitude 3340
Dell
Latitude 3410
Dell
Latitude 3420
Dell
Latitude 3430
Dell
Latitude 3440
Dell
Latitude 3450
Dell
Latitude 3510
Dell
Latitude 3520
Dell
Latitude 3530
Dell
Latitude 3540
Dell
Latitude 3550
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects the BIOS password recovery mechanism on the Dell Pro 14 Essential PV14250 platform. The weakness in the recovery process could be exploited by an attacker who has physical access to the device, enabling unauthorized access without authentication. The CVSS 3.1 vector indicates the attack requires physical access (AV:P), has low attack complexity (AC:L), requires no privileges (PR:N), no user interaction (UI:N), and impacts confidentiality, integrity, and availability to a limited extent (C:L/I:L/A:L). No patch or official remediation level has been published by Dell as of the data provided.
Potential Impact
An attacker with physical access to the affected Dell system could exploit the weak password recovery mechanism to bypass authentication controls, potentially gaining unauthorized access to the BIOS or system settings. This could lead to limited confidentiality, integrity, and availability impacts as indicated by the CVSS score. Remote exploitation is not possible due to the physical access requirement. No known exploits have been reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, physical security controls should be enforced to prevent unauthorized physical access to affected devices. Monitor Dell's advisories for updates on patches or mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- dell
- Date Reserved
- 2025-04-15T21:30:44.885Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 69e10ef782d89c981fa32a50
Added to database: 04/16/2026, 16:31:51 UTC
Last enriched: 05/27/2026, 19:55:46 UTC
Last updated: 09/13/2026, 22:50:35 UTC
Views: 251
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.