8.2

CVE-2021-21522

Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellLatitude 7210 2-in-1 Firmware Version < 1.7.0
   DellLatitude 7210 2-in-1 Version-
DellLatitude 7280 Firmware Version < 1.21.1
   DellLatitude 7280 Version-
DellLatitude 7280 Firmware Version1.21.1
   DellLatitude 7280 Version-
DellLatitude 7290 Firmware Version < 1.20.0
   DellLatitude 7290 Version-
DellLatitude 7290 Firmware Version1.20.0
   DellLatitude 7290 Version-
DellLatitude 7285 Firmware Version < 1.11.0
   DellLatitude 7285 Version-
DellLatitude 7285 Firmware Version1.11.0
   DellLatitude 7285 Version-
DellLatitude 7370 Firmware Version < 1.24.3
   DellLatitude 7370 Version-
DellLatitude 7370 Firmware Version1.24.3
   DellLatitude 7370 Version-
DellLatitude 7310 Firmware Version < 1.7.0
   DellLatitude 7310 Version-
DellLatitude 7380 Firmware Version1.21.1
   DellLatitude 7380 Version-
DellLatitude 7389 Firmware Version < 1.23.1
   DellLatitude 7389 Version-
DellLatitude 7390 Firmware Version1.20.0
   DellLatitude 7390 Version-
DellLatitude 7410 Firmware Version < 1.7.0
   DellLatitude 7410 Version-
DellLatitude 7390 2-in-1 Firmware Version < 1.19.0
   DellLatitude 7390 2-in-1 Version-
DellLatitude 7420 Firmware Version < 1.7.1
   DellLatitude 7420 Version-
DellLatitude 7480 Firmware Version < 1.21.1
   DellLatitude 7480 Version-
DellLatitude 7490 Firmware Version < 1.20.1
   DellLatitude 7490 Version-
DellLatitude 9410 Firmware Version < 1.7.0
   DellLatitude 9410 Version-
DellLatitude 9510 Firmware Version < 1.6.0
   DellLatitude 9510 Version-
DellPrecision 3640 Tower Firmware Version < 1.6.2
   DellPrecision 3640 Tower Version-
DellPrecision 5520 Firmware Version < 1.23.1
   DellPrecision 5520 Version-
DellPrecision 5510 Firmware Version < 1.17.0
   DellPrecision 5510 Version-
DellPrecision 5530 2-in-1 Firmware Version < 1.14.10
   DellPrecision 5530 2-in-1 Version-
DellXps 13 9360 Firmware Version < 2.16.0
   DellXps 13 9360 Version-
DellXps 13 9370 Firmware Version < 1.15.0
   DellXps 13 9370 Version-
DellXps 15 9575 2-in-1 Firmware Version < 1.16.2
   DellXps 15 9575 2-in-1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
security_alert@emc.com 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H