SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21573

Dell BIOSConnect feature contains a buffer overflow vulnerability.

HIGH 7.5EPSS 0.28%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
0.28% probability · 20th percentile
CISA KEV
Not listed
Weakness
CWE-121, CWE-787
Affected
dell/alienware m15 r6 firmware · dell/chengming 3990 firmware · dell/chengming 3991 firmware · dell/g15 5510 firmware · dell/g15 5511 firmware · dell/g3 3500 firmware · dell/g5 5500 firmware · dell/g7 7500 firmware · dell/g7 7700 firmware · dell/inspiron 14 5418 firmware · dell/inspiron 15 5518 firmware · dell/inspiron 15 7510 firmware · dell/inspiron 3501 firmware · dell/inspiron 3880 firmware · dell/inspiron 3881 firmware · dell/inspiron 3891 firmware · dell/inspiron 5300 firmware · dell/inspiron 5301 firmware · dell/inspiron 5310 firmware · dell/inspiron 5400 2-in-1 firmware · +40 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.