V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-21572
CVE
High

Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system ma…

CVSS
7.5
High
EPSS
0.00
p17
Published
2021-01-01
Updated
2021-01-01
Description

Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

Tags · CWE
CWE-122
CAPEC-92
Affected products
Alienware_m15_r6_firmwareChengming_3990_firmwareChengming_3991_firmwareG15_5510_firmwareG15_5511_firmwareG3_3500_firmwareG5_5500_firmwareG7_7500_firmwareG7_7700_firmwareInspiron_14_5418_firmwareInspiron_15_5518_firmwareInspiron_15_7510_firmwareInspiron_3501_firmwareInspiron_3880_firmwareInspiron_3881_firmwareInspiron_3891_firmwareInspiron_5300_firmwareInspiron_5301_firmwareInspiron_5310_firmwareInspiron_5400_2-in-1_firmware
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: H
High (H)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p17
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
alienware_m15_r6_firmware*Tracked
chengming_3990_firmware*Tracked
chengming_3991_firmware*Tracked
g15_5510_firmware*Tracked
g15_5511_firmware*Tracked
g3_3500_firmware*Tracked
g5_5500_firmware*Tracked
g7_7500_firmware*Tracked
g7_7700_firmware*Tracked
inspiron_14_5418_firmware*Tracked
inspiron_15_5518_firmware*Tracked
inspiron_15_7510_firmware*Tracked
inspiron_3501_firmware*Tracked
inspiron_3880_firmware*Tracked
inspiron_3881_firmware*Tracked
inspiron_3891_firmware*Tracked
inspiron_5300_firmware*Tracked
inspiron_5301_firmware*Tracked
inspiron_5310_firmware*Tracked
inspiron_5400_2-in-1_firmware*Tracked
Showing first 20 of 128
Source databases
CVE