4.4

CVE-2021-21522

Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Latitude 7210 2-in-1 Firmware Version < 1.7.0
   Dell ≫ Latitude 7210 2-in-1 Version -
Dell ≫ Latitude 7280 Firmware Version < 1.21.1
   Dell ≫ Latitude 7280 Version -
Dell ≫ Latitude 7280 Firmware Version 1.21.1
   Dell ≫ Latitude 7280 Version -
Dell ≫ Latitude 7290 Firmware Version < 1.20.0
   Dell ≫ Latitude 7290 Version -
Dell ≫ Latitude 7290 Firmware Version 1.20.0
   Dell ≫ Latitude 7290 Version -
Dell ≫ Latitude 7285 Firmware Version < 1.11.0
   Dell ≫ Latitude 7285 Version -
Dell ≫ Latitude 7285 Firmware Version 1.11.0
   Dell ≫ Latitude 7285 Version -
Dell ≫ Latitude 7370 Firmware Version < 1.24.3
   Dell ≫ Latitude 7370 Version -
Dell ≫ Latitude 7370 Firmware Version 1.24.3
   Dell ≫ Latitude 7370 Version -
Dell ≫ Latitude 7310 Firmware Version < 1.7.0
   Dell ≫ Latitude 7310 Version -
Dell ≫ Latitude 7380 Firmware Version 1.21.1
   Dell ≫ Latitude 7380 Version -
Dell ≫ Latitude 7389 Firmware Version < 1.23.1
   Dell ≫ Latitude 7389 Version -
Dell ≫ Latitude 7390 Firmware Version 1.20.0
   Dell ≫ Latitude 7390 Version -
Dell ≫ Latitude 7410 Firmware Version < 1.7.0
   Dell ≫ Latitude 7410 Version -
Dell ≫ Latitude 7390 2-in-1 Firmware Version < 1.19.0
   Dell ≫ Latitude 7390 2-in-1 Version -
Dell ≫ Latitude 7420 Firmware Version < 1.7.1
   Dell ≫ Latitude 7420 Version -
Dell ≫ Latitude 7480 Firmware Version < 1.21.1
   Dell ≫ Latitude 7480 Version -
Dell ≫ Latitude 7490 Firmware Version < 1.20.1
   Dell ≫ Latitude 7490 Version -
Dell ≫ Latitude 9410 Firmware Version < 1.7.0
   Dell ≫ Latitude 9410 Version -
Dell ≫ Latitude 9510 Firmware Version < 1.6.0
   Dell ≫ Latitude 9510 Version -
Dell ≫ Precision 3640 Tower Firmware Version < 1.6.2
   Dell ≫ Precision 3640 Tower Version -
Dell ≫ Precision 5520 Firmware Version < 1.23.1
   Dell ≫ Precision 5520 Version -
Dell ≫ Precision 5510 Firmware Version < 1.17.0
   Dell ≫ Precision 5510 Version -
Dell ≫ Precision 5530 2-in-1 Firmware Version < 1.14.10
   Dell ≫ Precision 5530 2-in-1 Version -
Dell ≫ Xps 13 9360 Firmware Version < 2.16.0
   Dell ≫ Xps 13 9360 Version -
Dell ≫ Xps 13 9370 Firmware Version < 1.15.0
   Dell ≫ Xps 13 9370 Version -
Dell ≫ Xps 15 9575 2-in-1 Firmware Version < 1.16.2
   Dell ≫ Xps 15 9575 2-in-1 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.144
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
EMC 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.dell.com/support/kbdoc/000191495
Vendor Advisory