Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash

Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets (TL-2026-1200), also tracked as DSA-2026-197, is a high-severity software vulnerability scored CVSS 5.7, first published 2026-07-11 and last reviewed 2026-07-18. It has no confirmed attribution, affects Dell Edge Gateway 3000, references 1 CVE (CVE-2026-40639), maps to 21 MITRE ATT&CK techniques (T1005, T1052, T1068), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-1200

Threat ID
TL-2026-1200
Also known as
DSA-2026-197
Severity
HIGH
CVSS
5.7 (CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-11
Last reviewed
2026-07-18
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, health, finance, manufacturing, retail, education, technology
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
26
Updates
2026-07-18 · revalidated 1× · latest source

Malware and tooling in Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets

Malware and tooling: DMAReaper, IFRExtractor, PCILeech, UEFITool, flashrom

Dell Client Platform BIOS encodes admin/setup passwords with a flawed repeating 20-byte XOR key applied to a 32-byte field instead of cryptographic hashing, leaving the first character unencrypted and leaking key material for passwords of 12 characters or fewer. An attacker with physical access to the SPI flash chip (or an attacker-controlled OS boot) can dump the DVAR region and recover the admin password offline.

How Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets works

CVE-2026-40639 (Dell Security Advisory DSA-2026-197) is a Weak Encoding for Password vulnerability (CWE-261) in Dell Client Platform BIOS, discovered by Craig S. Blackie of MDSec and Darren McDonald of AmberWolf and privately disclosed to Dell in March 2026. Instead of using a salted cryptographic hash, Dell's BIOS setup/admin password is obfuscated by XORing the password against a repeating 20-byte device key across a fixed 32-byte storage field in the BIOS DVAR (Dell Variable) NVRAM region held in SPI flash. This construction has three independently exploitable weaknesses: (1) the first character of the password is stored completely unencrypted, immediately leaking one byte of plaintext; (2) for passwords of 12 characters or fewer, the remaining bytes of the 32-byte field are null-padded, and XORing a known zero byte against the stored ciphertext directly reveals the corresponding raw key bytes, allowing full key reconstruction without any password knowledge; (3) even for longer passwords where the padding trick does not apply, the per-device key is derived from a fixed seed combined with the system GUID and has only 256 possible values, making brute-force key recovery trivial once a flash dump is obtained. A further weakness is that historical DVAR records from earlier (shorter) passwords are not securely erased when a password is changed, so an attacker who obtains a flash dump can sometimes recover key material from a stale record even if the current password is long and 'safe.'

Exploitation requires either physical access to desolder/clip onto the SPI flash chip with an external programmer, or the ability to boot an attacker-controlled OS/utility (e.g. via flashrom) capable of reading the BIOS region while pre-boot protections have not yet locked flash access. This is consistent with MDSec's related March 2026 research ('Disabling Security Features in a Locked BIOS'), which used `flashrom -p internal -r dump.bin --ifd -i bios` and physical SPI clips to dump and later reflash modified firmware to Dell Latitude/Precision-class devices, and separately demonstrated patching NVRAM Setup variables (e.g. the VarStoreId 0x1 'Control Iommu Pre-boot Behavior' option at VarOffset 0x975 within GUID EC87D643-EBA4-4BB5-A1E5-3F3E36B20DA9) to silently disable Kernel DMA Protection while the UEFI menu still reports it as enabled -- persisting across official firmware updates. Combined with recovered BIOS admin credentials, an attacker can re-enable manufacturing/service modes, alter boot-chain and DMA-protection settings, and in TPM-only BitLocker configurations, use PCIe DMA (via tools such as PCILeech) to bypass full-disk encryption and boot protections and obtain SYSTEM-level code execution.

Dell rated the flaw CVSS 3.1 5.7 (Medium) using vector AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N, reflecting the physical-access attack vector; the discovering researchers argued for a higher 6.1 score citing lower attack complexity than Dell's assessment. There is no public PoC exploit tool release and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of this writing; exploitation has not been observed in the wild. Dell began shipping patched BIOS releases on 2026-06-04 for the first affected models, with the advisory published 2026-06-09 and additional platform fixes (including the Wyse 5070 thin client) still pending as of late July 2026.

MITRE ATT&CK techniques used in TL-2026-1200

Collection

T1005 Data from Local System; T1119 Automated Collection

Exfiltration

T1052 Exfiltration Over Physical Medium

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1547 Boot or Logon Autostart Execution; T1547.006 Kernel Modules and Extensions; T1548 Abuse Elevation Control Mechanism

Initial Access

T1078 Valid Accounts; T1091 Replication Through Removable Media; T1200 Hardware Additions

Discovery

T1082 System Information Discovery

defense-impairment

T1112 Modify Registry; T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Impact

T1495 Firmware Corruption

Persistence

T1542 Pre-OS Boot; T1542.001 System Firmware

Credential Access

T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1556 Modify Authentication Process

Reconnaissance

T1592 Gather Victim Host Information

Affected products and versions in Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets

  • Dell — Edge Gateway 3000
    Vulnerable versions: < 1.26.0
    Fixed in: 1.26.0
  • Dell — Edge Gateway 5000
    Vulnerable versions: < 1.36.0
    Fixed in: 1.36.0
  • Dell — Embedded PC 3000
    Vulnerable versions: < 1.32.0
    Fixed in: 1.32.0
  • Dell — Embedded PC 5000
    Vulnerable versions: < 1.33.0
    Fixed in: 1.33.0
  • Dell — Latitude 3190 / 3190 2-in-1
    Vulnerable versions: < 1.44.0
    Fixed in: 1.44.0
  • Dell — Latitude 3310 / 3310 2-in-1
    Vulnerable versions: < 1.32.0
    Fixed in: 1.32.0-1.33.0
  • Dell — Latitude 7220 Rugged Extreme
    Vulnerable versions: < 1.51.0
    Fixed in: 1.51.0
  • Dell — Latitude Rugged 5420 / 5424 / 7424
    Vulnerable versions: < 1.42.0
    Fixed in: 1.42.0
  • Dell — OptiPlex 7070 Ultra Form Factor
    Vulnerable versions: < 1.36.1
    Fixed in: 1.36.1
  • Dell — Precision 3630 Tower
    Vulnerable versions: < 2.40.0
    Fixed in: 2.40.0

Remediation for Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets

Patches

  • Dell Edge Gateway 3000: upgrade to BIOS 1.26.0+ (released 06/09/2026)
  • Dell Edge Gateway 5000: upgrade to BIOS 1.36.0+ (released 06/08/2026)
  • Dell Embedded PC 3000: upgrade to BIOS 1.32.0+ (released 06/09/2026)
  • Dell Embedded PC 5000: upgrade to BIOS 1.33.0+ (released 06/08/2026)
  • Dell Latitude 3190 / 3190 2-in-1: upgrade to BIOS 1.44.0+ (released 06/16/2026)
  • Dell Latitude 3310 / 3310 2-in-1: upgrade to BIOS 1.32.0-1.33.0+ (released 06/11/2026)
  • Dell Latitude 7220 Rugged Extreme: upgrade to BIOS 1.51.0+ (released 06/08/2026)
  • Dell Latitude Rugged 5420/5424/7424: upgrade to BIOS 1.42.0+ (released 06/08/2026)
  • Dell OptiPlex 7070 Ultra Form Factor: upgrade to BIOS 1.36.1+ (released 06/10/2026)
  • Dell Precision 3630 Tower: upgrade to BIOS 2.40.0+ (released 06/04/2026)

Immediate actions

  • Inventory all Dell Client Platform devices (Latitude, XPS, Precision, Rugged, Wyse, OptiPlex, Edge Gateway, Embedded PC) and cross-reference BIOS versions against DSA-2026-197's fixed-version table.
  • Apply the patched BIOS via Dell Drivers & Downloads for every affected model listed in the advisory as fixes become available.
  • Restrict physical access to endpoints (locked enclosures, cable locks, chassis intrusion alarms) for devices awaiting a BIOS fix, especially rugged/field-deployed and thin-client hardware.
  • For devices relying on TPM-only BitLocker (no PIN), treat physical possession as a compromise risk until patched; consider temporarily requiring TPM+PIN or TPM+startup-key protectors.

Workarounds

  • Until patched, do not rely on the BIOS/setup admin password alone as a security boundary for physical possession threat models.
  • Disable or physically shield JTAG/SPI test points and debug headers where feasible on high-risk deployed hardware.
  • Enable full-disk encryption with a pre-boot PIN or USB startup key in addition to TPM, rather than TPM-only protectors, on affected models.

Longer-term hardening

  • Move BIOS/setup password storage policy toward vendor platforms that use salted, iterated cryptographic hashing (e.g. SHA-256-based vaults, as used in Dell OptiPlex 3000's SIVB) rather than reversible XOR obfuscation.
  • Require Kernel DMA Protection plus Secure Boot and measured boot (TPM PCR) validation, and monitor for PCR/measurement anomalies that could indicate offline firmware tampering.
  • Adopt endpoint firmware integrity monitoring (e.g. periodic SPI flash hash verification or vendor firmware-attestation tooling) to detect out-of-band flash modification.
  • Track vendor advisories for the remaining unpatched Dell platforms (e.g. Wyse 5070) and apply fixes as Dell completes its phased rollout through end of July 2026.

CVEs associated with Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets

CVE-2026-40639

Weaknesses (CWE) in Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets

CWE-261

Timeline of Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets

  • Craig S. Blackie (MDSec) and Darren McDonald (AmberWolf) identify the weak XOR password-encoding scheme while analyzing Wyse 5070 firmware for unrelated pre-boot DMA vulnerabilities.
  • Craig S. Blackie (MDSec) and Darren McDonald (AmberWolf) privately disclose the BIOS password XOR-encoding weakness (CVE-2026-40639) to Dell.
  • MDSec publishes related research 'Disabling Security Features in a Locked BIOS' documenting SPI flash dumping/reflashing and NVRAM Setup-variable tampering on Dell platforms.
  • Researchers submit joint private disclosure to Dell PSIRT, opening a 90-day coordinated disclosure window.
  • Researchers follow up with Dell PSIRT after receiving no initial response.
  • Dell validates the findings and requests an extended remediation target of July 31, 2026.
  • Disclosure deadline extended by mutual agreement to June 9, 2026.
  • Dell releases the first patched BIOS versions for Precision 3630 Tower (2.40.0) and Precision 3930 Rack (2.43.0).
  • Dell releases patched BIOS for Edge Gateway 5000 (1.36.0), Embedded PC 5000 (1.33.0), and Latitude 7220 Rugged Extreme (1.51.0) and Latitude Rugged 5420/5424/7424 (1.42.0).
  • Dell publishes Security Advisory DSA-2026-197 disclosing CVE-2026-40639 and releases patched BIOS for Edge Gateway 3000 (1.26.0) and Embedded PC 3000 (1.32.0).
  • Dell releases patched BIOS 1.36.1 for OptiPlex 7070 Ultra Form Factor.
  • Dell releases patched BIOS 1.32.0-1.33.0 for Latitude 3310 / 3310 2-in-1.
  • Dell releases patched BIOS 1.43.0 for Precision 5540.
  • Dell releases patched BIOS 1.44.0 for Latitude 3190 / 3190 2-in-1.
  • Researchers present 'Unlocked and Leaked: four methods through a locked Dell BIOS' at DC4420, London.
  • MDSec and AmberWolf publish joint technical write-up and release the dellpwn proof-of-concept recovery tool on GitHub.
  • Cyber Security News publishes coverage of the vulnerability and researcher disclosure, noting the Wyse 5070 thin client remains unpatched and additional fixes are targeted for end of July 2026.
  • Dell revises DSA-2026-197 to revision 3.0, adding further patched Latitude Rugged and OptiPlex UFF/XE3 firmware versions; Wyse 5070, Latitude E7250, XPS 15 9560, and Latitude 7490 remain confirmed-vulnerable and unpatched.
  • Vulnerability summarized in the CTO at NCSC weekly threat digest, flagging the unpatched Wyse 5070 as a practical, low-effort attack path.

Update history for TL-2026-1200

Sources cited for Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets

Threats related to Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets

Detection coverage for TL-2026-1200

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1200 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats