VulnerabilityModified
CVE-2021-21571
Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability.
MEDIUM 6.5EPSS 0.54%
Does this matter?
Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.
Description
Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- dell/alienware m15 r6 firmware · dell/chengming 3990 firmware · dell/chengming 3991 firmware · dell/g15 5510 firmware · dell/g15 5511 firmware · dell/g3 3500 firmware · dell/g5 5500 firmware · dell/g7 7500 firmware · dell/g7 7700 firmware · dell/inspiron 14 5418 firmware · dell/inspiron 15 5518 firmware · dell/inspiron 15 7510 firmware · dell/inspiron 3501 firmware · dell/inspiron 3880 firmware · dell/inspiron 3881 firmware · dell/inspiron 3891 firmware · dell/inspiron 5300 firmware · dell/inspiron 5301 firmware · dell/inspiron 5310 firmware · dell/inspiron 5400 2-in-1 firmware · +40 more
- Source
- security_alert@emc.com
References
- https://www.dell.com/support/kbdoc/en-us/000188682Vendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000188682Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.