{"id":"CVE-2026-35159","title":"Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability","summary":"Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L","cwe":["CWE-305"],"published":"2026-07-03","updated":"2026-07-03","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-35159","references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000452197/dsa-2026-195","label":"security_alert@emc.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-07-04T07:55:53.786Z","epss":0.00206,"epssPercentile":0.10926,"vendor":"Dell","product":"Inspiron 15 3520","affected":["inspiron_15_3520 < 1.41.0 or later","g15_5530 < 1.33.0 or later","alienware_16_area-51_aa16250 < 2.4.1 or later","alienware_16_aurora_ac16250 < 1.13.0 or later","alienware_16x_aurora_ac16251 < 2.4.0 or later","alienware_18_area-51_aa18250 < 2.4.1 or later","alienware_area-51_aat2250 < 1.17.2 or later","alienware_aurora_act1250 < 1.16.2 or later","alienware_m15_r6 < 1.44.0 or later","alienware_m15_r7 < 1.40.0 or later","alienware_m16_r1 < 1.34.0 or later","alienware_m16_r2 < 1.21.0 or later","alienware_m18_r1 < 1.34.0 or later","alienware_m18_r2 < 1.22.0 or later","alienware_x14_r2 < 1.32.0 or later","alienware_x16_r1 < 1.32.0 or later","alienware_x16_r2 < 1.22.0 or later","chengming_3900 < 1.40.0 or later","chengming_3910_3911 < 1.36.0 or later","14_dc14250 < 1.7.0 or later","14_plus_2-in-1_db04250 < 1.13.0 or later","14_plus_db14250 < 1.13.0 or later","15_dc15250 < 1.10.0 or later","16_plus_2-in-1_db06250 < 1.13.0 or later","16_plus_db16250 < 1.13.0 or later","24_all-in-one_ec24250 < 1.15.0 or later","27_all-in-one_ec27250 < 1.15.0 or later","g15_5510 < 1.40.0 or later","g15_5511 < 1.43.0 or later","g15_5520 < 1.41.0 or later","g16_7620 < 1.41.0 or later","g16_7630 < 1.33.0 or later","pro_13_plus_pb13250 < 2.13.4 or later","pro_13_plus_pb13255 < 1.15.0 or later","pro_13_premium_pa13250 < 2.13.4 or later","pro_14_essential_pv14250 < 1.6.0 or later","pro_14_pc14250 < 1.15.2 or later","pro_14_plus_pb14250 < 2.13.4 or later","pro_14_plus_pb14255 < 1.15.0 or later","pro_14_premium_pa14250 < 2.13.4 or later","pro_16_pc16250 < 1.15.2 or later","pro_16_plus_pb16250 < 2.13.4 or later","pro_16_plus_pb16255 < 1.15.0 or later","pro_24_all-in-one_plus_qb24250_pro_24_all-in-one_qc24250_pro_24_all-in-one_qc24251 < 1.15.1 or later","pro_laptop_pc14250 < 1.15.2 or later","pro_laptop_pc16250 < 1.15.2 or later","pro_max_14_mc14250 < 1.14.1 or later","pro_max_14_mc14255 < 2.4.0 or later","pro_max_16_mc16250 < 1.14.1 or later","pro_max_16_mc16255 < 2.4.0 or later"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-07T02:13:05.435803Z"},"slug":"CVE-2026-35159","body":"## Overview\n\nDell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}