Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-40639

Quick assessment

Affected
Dell Dell Edge Gateway 3000
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dell Client Platform BIOS是美国戴尔(Dell)公司的一个客户端平台 BIOS。 Dell Client Platform BIOS存在安全漏洞,该漏洞源于密码编码较弱,可能导致具有物理访问权限的未经验证攻击者提升权限。

CVSS 5.7 · Medium EPSS 0.19% · P9

Possible ATT&CK Techniques 1 AI

T1552.006 · Group Policy Preferences

Affected Version Matrix 12

VendorProduct Version RangeStatus
Dell Dell Edge Gateway 3000 < 1.26.0 affected
Dell Dell Edge Gateway 5000 < 1.36.0 affected
Dell DELL EMBEDDED PC 3000 < 1.32.0 affected
Dell DELL EMBEDDED PC 5000 < 1.33.0 affected
Dell Dell Precision 3630 Tower < 2.40.0 affected
Dell Dell Precision 3930 Rack < 2.43.0 affected
Dell Latitude 7220 Rugged Extreme < 1.51.0 affected
Dell Latitude Rugged 5420 < 1.42.0 affected
Dell Latitude Rugged 5424 < 1.42.0 affected
Dell Latitude Rugged 7220EX < 1.51.0 affected
Dell Latitude Rugged 7424 < 1.42.0 affected
Dell Precision 3930 Rack < 2.43.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-40639

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
口令使用弱密码学算法
Source: CVE Program / CVE List V5
Vulnerability Title
Dell Client Platform BIOS 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Dell Client Platform BIOS是美国戴尔(Dell)公司的一个客户端平台 BIOS。 Dell Client Platform BIOS存在安全漏洞,该漏洞源于密码编码较弱,可能导致具有物理访问权限的未经验证攻击者提升权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Dell Dell Edge Gateway 3000 0 ~ 1.26.0 -
Dell Dell Edge Gateway 5000 0 ~ 1.36.0 -
Dell DELL EMBEDDED PC 3000 0 ~ 1.32.0 -
Dell DELL EMBEDDED PC 5000 0 ~ 1.33.0 -
Dell Dell Precision 3630 Tower 0 ~ 2.40.0 -
Dell Dell Precision 3930 Rack 0 ~ 2.43.0 -
Dell Latitude 7220 Rugged Extreme 0 ~ 1.51.0 -
Dell Latitude Rugged 5420 0 ~ 1.42.0 -
Dell Latitude Rugged 5424 0 ~ 1.42.0 -
Dell Latitude Rugged 7220EX 0 ~ 1.51.0 -
Dell Latitude Rugged 7424 0 ~ 1.42.0 -
Dell Precision 3930 Rack 0 ~ 2.43.0 -

II. Public POCs for CVE-2026-40639

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-40639

登录查看更多情报信息。

Vendor Advisories for CVE-2026-40639 (1)

Same Patch Batch · Dell · 2026-06-09 · 4 CVEs total

CVE-2026-44275 6.3 MEDIUM Dell/Alienware Purchased Apps 后置链接漏洞
CVE-2026-41116 6.3 MEDIUM Dell Inventory Collector Client 安全漏洞
CVE-2026-28262 6.0 MEDIUM Dell iDRAC Tools 后置链接漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-40639

No comments yet


Leave a comment