8.1

CVE-2021-21557

Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management Mode.

Data is provided by the National Vulnerability Database (NVD)
DellPoweredge R640 Firmware Version < 2.11.2
   DellPoweredge R640 Version-
DellPoweredge R740 Firmware Version < 2.11.2
   DellPoweredge R740 Version-
DellPoweredge R740xd Firmware Version < 2.11.2
   DellPoweredge R740xd Version-
DellPoweredge R940 Firmware Version < 2.11.2
   DellPoweredge R940 Version-
DellPoweredge R540 Firmware Version < 2.11.2
   DellPoweredge R540 Version-
DellPoweredge R440 Firmware Version < 2.11.2
   DellPoweredge R440 Version-
DellPoweredge T440 Firmware Version < 2.11.2
   DellPoweredge T440 Version-
DellPoweredge Xr2 Firmware Version < 2.11.2
   DellPoweredge Xr2 Version-
DellPoweredge R740xd2 Firmware Version < 2.11.2
   DellPoweredge R740xd2 Version-
DellPoweredge R840 Firmware Version < 2.11.2
   DellPoweredge R840 Version-
DellPoweredge R940xa Firmware Version < 2.11.2
   DellPoweredge R940xa Version-
DellPoweredge T640 Firmware Version < 2.11.2
   DellPoweredge T640 Version-
DellPoweredge C6420 Firmware Version < 2.11.2
   DellPoweredge C6420 Version-
DellPoweredge Fc640 Firmware Version < 2.11.2
   DellPoweredge Fc640 Version-
DellPoweredge M640 Firmware Version < 2.11.2
   DellPoweredge M640 Version-
DellPoweredge M640p Firmware Version < 2.11.2
   DellPoweredge M640p Version-
DellPoweredge Mx740c Firmware Version < 2.11.2
   DellPoweredge Mx740c Version-
DellPoweredge Mx840c Firmware Version < 2.11.2
   DellPoweredge Mx840c Version-
DellPoweredge C4140 Firmware Version < 2.11.2
   DellPoweredge C4140 Version-
DellPoweredge T140 Firmware Version < 2.5.1
   DellPoweredge T140 Version-
DellPoweredge T340 Firmware Version < 2.5.1
   DellPoweredge T340 Version-
DellPoweredge R240 Firmware Version < 2.5.1
   DellPoweredge R240 Version-
DellPoweredge R340 Firmware Version < 2.5.1
   DellPoweredge R340 Version-
DellPoweredge R6415 Firmware Version < 1.16.1
   DellPoweredge R6415 Version-
DellPoweredge R7415 Firmware Version < 1.16.1
   DellPoweredge R7415 Version-
DellPoweredge R7425 Firmware Version < 1.16.1
   DellPoweredge R7425 Version-
DellPoweredge R6515 Firmware Version < 2.2.4
   DellPoweredge R6515 Version-
DellPoweredge R7515 Firmware Version < 2.2.4
   DellPoweredge R7515 Version-
DellPoweredge R6525 Firmware Version < 2.2.5
   DellPoweredge R6525 Version-
DellPoweredge R7525 Firmware Version < 2.2.5
   DellPoweredge R7525 Version-
DellPoweredge C6525 Firmware Version < 2.2.4
   DellPoweredge C6525 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.095
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
security_alert@emc.com 8.1 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.