Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash
Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets (TL-2026-1200), also tracked as DSA-2026-197, is a high-severity software vulnerability scored CVSS 5.7, first published 2026-07-11 and last reviewed 2026-07-18. It has no confirmed attribution, affects Dell Edge Gateway 3000, references 1 CVE (CVE-2026-40639), maps to 21 MITRE ATT&CK techniques (T1005, T1052, T1068), and is covered by 9 detection rules and 26 indicators of compromise.
Key facts for TL-2026-1200
- Threat ID
- TL-2026-1200
- Also known as
- DSA-2026-197
- Severity
- HIGH
- CVSS
- 5.7 (CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-11
- Last reviewed
- 2026-07-18
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, health, finance, manufacturing, retail, education, technology
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 26
- Updates
- 2026-07-18 · revalidated 1× · latest source
Malware and tooling in Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets
Malware and tooling: DMAReaper, IFRExtractor, PCILeech, UEFITool, flashrom
Dell Client Platform BIOS encodes admin/setup passwords with a flawed repeating 20-byte XOR key applied to a 32-byte field instead of cryptographic hashing, leaving the first character unencrypted and leaking key material for passwords of 12 characters or fewer. An attacker with physical access to the SPI flash chip (or an attacker-controlled OS boot) can dump the DVAR region and recover the admin password offline.
How Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets works
CVE-2026-40639 (Dell Security Advisory DSA-2026-197) is a Weak Encoding for Password vulnerability (CWE-261) in Dell Client Platform BIOS, discovered by Craig S. Blackie of MDSec and Darren McDonald of AmberWolf and privately disclosed to Dell in March 2026. Instead of using a salted cryptographic hash, Dell's BIOS setup/admin password is obfuscated by XORing the password against a repeating 20-byte device key across a fixed 32-byte storage field in the BIOS DVAR (Dell Variable) NVRAM region held in SPI flash. This construction has three independently exploitable weaknesses: (1) the first character of the password is stored completely unencrypted, immediately leaking one byte of plaintext; (2) for passwords of 12 characters or fewer, the remaining bytes of the 32-byte field are null-padded, and XORing a known zero byte against the stored ciphertext directly reveals the corresponding raw key bytes, allowing full key reconstruction without any password knowledge; (3) even for longer passwords where the padding trick does not apply, the per-device key is derived from a fixed seed combined with the system GUID and has only 256 possible values, making brute-force key recovery trivial once a flash dump is obtained. A further weakness is that historical DVAR records from earlier (shorter) passwords are not securely erased when a password is changed, so an attacker who obtains a flash dump can sometimes recover key material from a stale record even if the current password is long and 'safe.'
Exploitation requires either physical access to desolder/clip onto the SPI flash chip with an external programmer, or the ability to boot an attacker-controlled OS/utility (e.g. via flashrom) capable of reading the BIOS region while pre-boot protections have not yet locked flash access. This is consistent with MDSec's related March 2026 research ('Disabling Security Features in a Locked BIOS'), which used `flashrom -p internal -r dump.bin --ifd -i bios` and physical SPI clips to dump and later reflash modified firmware to Dell Latitude/Precision-class devices, and separately demonstrated patching NVRAM Setup variables (e.g. the VarStoreId 0x1 'Control Iommu Pre-boot Behavior' option at VarOffset 0x975 within GUID EC87D643-EBA4-4BB5-A1E5-3F3E36B20DA9) to silently disable Kernel DMA Protection while the UEFI menu still reports it as enabled -- persisting across official firmware updates. Combined with recovered BIOS admin credentials, an attacker can re-enable manufacturing/service modes, alter boot-chain and DMA-protection settings, and in TPM-only BitLocker configurations, use PCIe DMA (via tools such as PCILeech) to bypass full-disk encryption and boot protections and obtain SYSTEM-level code execution.
Dell rated the flaw CVSS 3.1 5.7 (Medium) using vector AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N, reflecting the physical-access attack vector; the discovering researchers argued for a higher 6.1 score citing lower attack complexity than Dell's assessment. There is no public PoC exploit tool release and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of this writing; exploitation has not been observed in the wild. Dell began shipping patched BIOS releases on 2026-06-04 for the first affected models, with the advisory published 2026-06-09 and additional platform fixes (including the Wyse 5070 thin client) still pending as of late July 2026.
MITRE ATT&CK techniques used in TL-2026-1200
Collection
T1005 Data from Local System; T1119 Automated Collection
Exfiltration
T1052 Exfiltration Over Physical Medium
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1547 Boot or Logon Autostart Execution; T1547.006 Kernel Modules and Extensions; T1548 Abuse Elevation Control Mechanism
Initial Access
T1078 Valid Accounts; T1091 Replication Through Removable Media; T1200 Hardware Additions
Discovery
T1082 System Information Discovery
defense-impairment
T1112 Modify Registry; T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
Impact
Persistence
T1542 Pre-OS Boot; T1542.001 System Firmware
Credential Access
T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1556 Modify Authentication Process
Reconnaissance
Affected products and versions in Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets
- Dell — Edge Gateway 3000
Vulnerable versions: < 1.26.0
Fixed in: 1.26.0 - Dell — Edge Gateway 5000
Vulnerable versions: < 1.36.0
Fixed in: 1.36.0 - Dell — Embedded PC 3000
Vulnerable versions: < 1.32.0
Fixed in: 1.32.0 - Dell — Embedded PC 5000
Vulnerable versions: < 1.33.0
Fixed in: 1.33.0 - Dell — Latitude 3190 / 3190 2-in-1
Vulnerable versions: < 1.44.0
Fixed in: 1.44.0 - Dell — Latitude 3310 / 3310 2-in-1
Vulnerable versions: < 1.32.0
Fixed in: 1.32.0-1.33.0 - Dell — Latitude 7220 Rugged Extreme
Vulnerable versions: < 1.51.0
Fixed in: 1.51.0 - Dell — Latitude Rugged 5420 / 5424 / 7424
Vulnerable versions: < 1.42.0
Fixed in: 1.42.0 - Dell — OptiPlex 7070 Ultra Form Factor
Vulnerable versions: < 1.36.1
Fixed in: 1.36.1 - Dell — Precision 3630 Tower
Vulnerable versions: < 2.40.0
Fixed in: 2.40.0
Remediation for Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets
Patches
- Dell Edge Gateway 3000: upgrade to BIOS 1.26.0+ (released 06/09/2026)
- Dell Edge Gateway 5000: upgrade to BIOS 1.36.0+ (released 06/08/2026)
- Dell Embedded PC 3000: upgrade to BIOS 1.32.0+ (released 06/09/2026)
- Dell Embedded PC 5000: upgrade to BIOS 1.33.0+ (released 06/08/2026)
- Dell Latitude 3190 / 3190 2-in-1: upgrade to BIOS 1.44.0+ (released 06/16/2026)
- Dell Latitude 3310 / 3310 2-in-1: upgrade to BIOS 1.32.0-1.33.0+ (released 06/11/2026)
- Dell Latitude 7220 Rugged Extreme: upgrade to BIOS 1.51.0+ (released 06/08/2026)
- Dell Latitude Rugged 5420/5424/7424: upgrade to BIOS 1.42.0+ (released 06/08/2026)
- Dell OptiPlex 7070 Ultra Form Factor: upgrade to BIOS 1.36.1+ (released 06/10/2026)
- Dell Precision 3630 Tower: upgrade to BIOS 2.40.0+ (released 06/04/2026)
Immediate actions
- Inventory all Dell Client Platform devices (Latitude, XPS, Precision, Rugged, Wyse, OptiPlex, Edge Gateway, Embedded PC) and cross-reference BIOS versions against DSA-2026-197's fixed-version table.
- Apply the patched BIOS via Dell Drivers & Downloads for every affected model listed in the advisory as fixes become available.
- Restrict physical access to endpoints (locked enclosures, cable locks, chassis intrusion alarms) for devices awaiting a BIOS fix, especially rugged/field-deployed and thin-client hardware.
- For devices relying on TPM-only BitLocker (no PIN), treat physical possession as a compromise risk until patched; consider temporarily requiring TPM+PIN or TPM+startup-key protectors.
Workarounds
- Until patched, do not rely on the BIOS/setup admin password alone as a security boundary for physical possession threat models.
- Disable or physically shield JTAG/SPI test points and debug headers where feasible on high-risk deployed hardware.
- Enable full-disk encryption with a pre-boot PIN or USB startup key in addition to TPM, rather than TPM-only protectors, on affected models.
Longer-term hardening
- Move BIOS/setup password storage policy toward vendor platforms that use salted, iterated cryptographic hashing (e.g. SHA-256-based vaults, as used in Dell OptiPlex 3000's SIVB) rather than reversible XOR obfuscation.
- Require Kernel DMA Protection plus Secure Boot and measured boot (TPM PCR) validation, and monitor for PCR/measurement anomalies that could indicate offline firmware tampering.
- Adopt endpoint firmware integrity monitoring (e.g. periodic SPI flash hash verification or vendor firmware-attestation tooling) to detect out-of-band flash modification.
- Track vendor advisories for the remaining unpatched Dell platforms (e.g. Wyse 5070) and apply fixes as Dell completes its phased rollout through end of July 2026.
CVEs associated with Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets
CVE-2026-40639
Weaknesses (CWE) in Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets
CWE-261
Timeline of Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets
- Craig S. Blackie (MDSec) and Darren McDonald (AmberWolf) identify the weak XOR password-encoding scheme while analyzing Wyse 5070 firmware for unrelated pre-boot DMA vulnerabilities.
- Craig S. Blackie (MDSec) and Darren McDonald (AmberWolf) privately disclose the BIOS password XOR-encoding weakness (CVE-2026-40639) to Dell.
- MDSec publishes related research 'Disabling Security Features in a Locked BIOS' documenting SPI flash dumping/reflashing and NVRAM Setup-variable tampering on Dell platforms.
- Researchers submit joint private disclosure to Dell PSIRT, opening a 90-day coordinated disclosure window.
- Researchers follow up with Dell PSIRT after receiving no initial response.
- Dell validates the findings and requests an extended remediation target of July 31, 2026.
- Disclosure deadline extended by mutual agreement to June 9, 2026.
- Dell releases the first patched BIOS versions for Precision 3630 Tower (2.40.0) and Precision 3930 Rack (2.43.0).
- Dell releases patched BIOS for Edge Gateway 5000 (1.36.0), Embedded PC 5000 (1.33.0), and Latitude 7220 Rugged Extreme (1.51.0) and Latitude Rugged 5420/5424/7424 (1.42.0).
- Dell publishes Security Advisory DSA-2026-197 disclosing CVE-2026-40639 and releases patched BIOS for Edge Gateway 3000 (1.26.0) and Embedded PC 3000 (1.32.0).
- Dell releases patched BIOS 1.36.1 for OptiPlex 7070 Ultra Form Factor.
- Dell releases patched BIOS 1.32.0-1.33.0 for Latitude 3310 / 3310 2-in-1.
- Dell releases patched BIOS 1.43.0 for Precision 5540.
- Dell releases patched BIOS 1.44.0 for Latitude 3190 / 3190 2-in-1.
- Researchers present 'Unlocked and Leaked: four methods through a locked Dell BIOS' at DC4420, London.
- MDSec and AmberWolf publish joint technical write-up and release the dellpwn proof-of-concept recovery tool on GitHub.
- Cyber Security News publishes coverage of the vulnerability and researcher disclosure, noting the Wyse 5070 thin client remains unpatched and additional fixes are targeted for end of July 2026.
- Dell revises DSA-2026-197 to revision 3.0, adding further patched Latitude Rugged and OptiPlex UFF/XE3 firmware versions; Wyse 5070, Latitude E7250, XPS 15 9560, and Latitude 7490 remain confirmed-vulnerable and unpatched.
- Vulnerability summarized in the CTO at NCSC weekly threat digest, flagging the unpatched Wyse 5070 as a practical, low-effort attack path.
Update history for TL-2026-1200
- 2026-07-18 — CVE-2026-40639: Dell BIOS Weak XOR Encryption Exposes Recoverable Passwords (DSA-2026-197): What changed Exploitability THEORETICAL → POC_PUBLIC after MDSec/AmberWolf publicly released the 'dellpwn' recovery tool and a technical write-up (2026-07-10); severity HIGH (this report's assessment) vs the existing record's MEDIUM given t
Sources cited for Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets
- Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash
- DSA-2026-197: Security Update for Dell Client Platform BIOS for a Weak Encoding for Password Vulnerability
- DSA-2026-197 (UK mirror)
- CVE-2026-40639 - Dell Client Platform BIOS Weak Encoding Password Elevation of Privilege
- Disabling Security Features in a Locked BIOS
- CISA Known Exploited Vulnerabilities Catalog
Threats related to Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets
- usbliter8 — checkm8-style unpatchable BootROM/SecureROM exploit for Apple A12/A13 (and S4/S5) devices
- usbliter8 — Unpatchable SecureROM Boot-Chain Code Execution on Apple A12/A13 (and S4/S5) SoCs via DWC2 USB DMA Underflow
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)
- usbliter8 — Unpatchable BootROM USB DMA Exploit on Apple A12/A12X/A12Z/A13 and S4/S5 Chips Bypassing Secure Boot
- "Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)
- Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related: CVE-2024-23630, CVE-2022-34885)
Detection coverage for TL-2026-1200
As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1200 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.