SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21571

Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability.

MEDIUM 6.5EPSS 0.54%

Does this matter?

Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.

Description

Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
EPSS
0.54% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
dell/alienware m15 r6 firmware · dell/chengming 3990 firmware · dell/chengming 3991 firmware · dell/g15 5510 firmware · dell/g15 5511 firmware · dell/g3 3500 firmware · dell/g5 5500 firmware · dell/g7 7500 firmware · dell/g7 7700 firmware · dell/inspiron 14 5418 firmware · dell/inspiron 15 5518 firmware · dell/inspiron 15 7510 firmware · dell/inspiron 3501 firmware · dell/inspiron 3880 firmware · dell/inspiron 3881 firmware · dell/inspiron 3891 firmware · dell/inspiron 5300 firmware · dell/inspiron 5301 firmware · dell/inspiron 5310 firmware · dell/inspiron 5400 2-in-1 firmware · +40 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.