7.5

CVE-2021-21572

Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

Data is provided by the National Vulnerability Database (NVD)
DellAlienware M15 R6 Firmware Version < 1.3.3
   DellAlienware M15 R6 Version-
DellChengming 3990 Firmware Version < 1.4.1
   DellChengming 3990 Version-
DellChengming 3991 Firmware Version < 1.4.1
   DellChengming 3991 Version-
DellG15 5510 Firmware Version < 1.4.0
   DellG15 5510 Version-
DellG15 5511 Firmware Version < 1.3.3
   DellG15 5511 Version-
DellG3 3500 Firmware Version <= 1.9.0
   DellG3 3500 Version-
DellG5 5500 Firmware Version < 1.9.0
   DellG5 5500 Version-
DellG7 7500 Firmware Version < 1.9.0
   DellG7 7500 Version-
DellG7 7700 Firmware Version < 1.9.0
   DellG7 7700 Version-
DellInspiron 14 5418 Firmware Version < 2.1.0_a06
   DellInspiron 14 5418 Version-
DellInspiron 15 5518 Firmware Version < 2.1.0_a06
   DellInspiron 15 5518 Version-
DellInspiron 15 7510 Firmware Version < 1.0.4
   DellInspiron 15 7510 Version-
DellInspiron 3501 Firmware Version < 1.6.0
   DellInspiron 3501 Version-
DellInspiron 3880 Firmware Version < 1.4.1
   DellInspiron 3880 Version-
DellInspiron 3881 Firmware Version < 1.4.1
   DellInspiron 3881 Version-
DellInspiron 3891 Firmware Version < 1.0.11
   DellInspiron 3891 Version-
DellInspiron 5300 Firmware Version < 1.7.1
   DellInspiron 5300 Version-
DellInspiron 5301 Firmware Version < 1.8.1
   DellInspiron 5301 Version-
DellInspiron 5310 Firmware Version < 2.1.0
   DellInspiron 5310 Version-
DellInspiron 5400 2-in-1 Firmware Version < 1.7.0
   DellInspiron 5400 2-in-1 Version-
DellInspiron 5400 Aio Firmware Version < 1.4.0
   DellInspiron 5400 Aio Version-
DellInspiron 5401 Firmware Version < 1.7.2
   DellInspiron 5401 Version-
DellInspiron 5401 Aio Firmware Version < 1.4.0
   DellInspiron 5401 Aio Version-
DellInspiron 5402 Firmware Version < 1.5.1
   DellInspiron 5402 Version-
DellInspiron 5406 2n1 Firmware Version < 1.5.1
   DellInspiron 5406 2n1 Version-
DellInspiron 5408 Firmware Version < 1.7.2
   DellInspiron 5408 Version-
DellInspiron 5409 Firmware Version < 1.5.1
   DellInspiron 5409 Version-
DellInspiron 5410 2-in-1 Firmware Version < 2.1.0
   DellInspiron 5410 2-in-1 Version-
DellInspiron 5501 Firmware Version < 1.7.2
   DellInspiron 5501 Version-
DellInspiron 5502 Firmware Version < 1.5.1
   DellInspiron 5502 Version-
DellInspiron 5508 Firmware Version < 1.7.2
   DellInspiron 5508 Version-
DellInspiron 5509 Firmware Version < 1.5.1
   DellInspiron 5509 Version-
DellInspiron 7300 Firmware Version < 1.8.1
   DellInspiron 7300 Version-
DellInspiron 7300 2-in-1 Firmware Version < 1.3.0
   DellInspiron 7300 2-in-1 Version-
DellInspiron 7306 2-in-1 Firmware Version < 1.5.1
   DellInspiron 7306 2-in-1 Version-
DellInspiron 7400 Firmware Version < 1.8.1
   DellInspiron 7400 Version-
DellInspiron 7500 Firmware Version < 1.8.0
   DellInspiron 7500 Version-
DellInspiron 7500 2-in-1 Firmware Version < 1.3.0
   DellInspiron 7500 2-in-1 Version-
DellInspiron 7501 Firmware Version < 1.8.0
   DellInspiron 7501 Version-
DellInspiron 7506 Firmware Version < 1.5.1
   DellInspiron 7506 Version-
DellInspiron 7610 Firmware Version < 1.0.4
   DellInspiron 7610 Version-
DellInspiron 7700 Aio Firmware Version < 1.4.0
   DellInspiron 7700 Aio Version-
DellInspiron 7706 2-in-1 Firmware Version < 1.5.1
   DellInspiron 7706 2-in-1 Version-
DellLatitude 3120 Firmware Version < 1.1.0
   DellLatitude 3120 Version-
DellLatitude 3320 Firmware Version < 1.4.0
   DellLatitude 3320 Version-
DellLatitude 3410 Firmware Version < 1.9.0
   DellLatitude 3410 Version-
DellLatitude 3420 Firmware Version < 1.8.0
   DellLatitude 3420 Version-
DellLatitude 3510 Firmware Version < 1.9.0
   DellLatitude 3510 Version-
DellLatitude 3520 Firmware Version < 1.8.0
   DellLatitude 3520 Version-
DellLatitude 5310 Firmware Version < 1.7.0
   DellLatitude 5310 Version-
DellLatitude 5310 2-in-1 Firmware Version < 1.7.0
   DellLatitude 5310 2-in-1 Version-
DellLatitude 5320 Firmware Version < 1.7.1
   DellLatitude 5320 Version-
DellLatitude 5320 2-in-1 Firmware Version < 1.7.1
   DellLatitude 5320 2-in-1 Version-
DellLatitude 5410 Firmware Version < 1.6.0
   DellLatitude 5410 Version-
DellLatitude 5411 Firmware Version < 1.6.0
   DellLatitude 5411 Version-
DellLatitude 5420 Firmware Version < 1.8.0
   DellLatitude 5420 Version-
DellLatitude 5510 Firmware Version < 1.6.0
   DellLatitude 5510 Version-
DellLatitude 5511 Firmware Version < 1.6.0
   DellLatitude 5511 Version-
DellLatitude 5520 Firmware Version < 1.7.1
   DellLatitude 5520 Version-
DellLatitude 5521 Firmware Version < 1.3.0_a03
   DellLatitude 5521 Version-
DellLatitude 7210 2-in-1 Firmware Version < 1.7.0
   DellLatitude 7210 2-in-1 Version-
DellLatitude 7310 Firmware Version < 1.7.0
   DellLatitude 7310 Version-
DellLatitude 7320 Firmware Version < 1.7.1
   DellLatitude 7320 Version-
DellLatitude 7320 Detachable Firmware Version < 1.4.0_a04
   DellLatitude 7320 Detachable Version-
DellLatitude 7410 Firmware Version < 1.7.0
   DellLatitude 7410 Version-
DellLatitude 7420 Firmware Version < 1.7.1
   DellLatitude 7420 Version-
DellLatitude 7520 Firmware Version < 1.7.1
   DellLatitude 7520 Version-
DellLatitude 9410 Firmware Version < 1.7.0
   DellLatitude 9410 Version-
DellLatitude 9420 Firmware Version < 1.4.1
   DellLatitude 9420 Version-
DellLatitude 9510 Firmware Version < 1.6.0
   DellLatitude 9510 Version-
DellLatitude 9520 Firmware Version < 1.5.2
   DellLatitude 9520 Version-
DellLatitude 5421 Firmware Version < 1.3.0_a03
   DellLatitude 5421 Version-
DellOptiplex 3080 Firmware Version < 2.1.1
   DellOptiplex 3080 Version-
DellOptiplex 3090 Uff Firmware Version < 1.2.0
   DellOptiplex 3090 Uff Version-
DellOptiplex 5080 Firmware Version < 1.4.0
   DellOptiplex 5080 Version-
DellOptiplex 5090 Tower Firmware Version < 1.1.35
   DellOptiplex 5090 Tower Version-
DellOptiplex 5490 Aio Firmware Version < 1.3.0
   DellOptiplex 5490 Aio Version-
DellOptiplex 7080 Firmware Version < 1.4.0
   DellOptiplex 7080 Version-
DellOptiplex 7090 Tower Firmware Version < 1.1.35
   DellOptiplex 7090 Tower Version-
DellOptiplex 7090 Uff Firmware Version < 1.2.0
   DellOptiplex 7090 Uff Version-
DellPrecision 17 M5750 Firmware Version < 1.8.2
   DellPrecision 17 M5750 Version-
DellPrecision 3440 Firmware Version < 1.4.0
   DellPrecision 3440 Version-
DellPrecision 3450 Firmware Version < 1.1.35
   DellPrecision 3450 Version-
DellPrecision 3550 Firmware Version < 1.6.0
   DellPrecision 3550 Version-
DellPrecision 3551 Firmware Version < 1.6.0
   DellPrecision 3551 Version-
DellPrecision 3560 Firmware Version < 1.7.1
   DellPrecision 3560 Version-
DellPrecision 3561 Firmware Version < 1.3.0_a03
   DellPrecision 3561 Version-
DellPrecision 3640 Firmware Version < 1.6.2
   DellPrecision 3640 Version-
DellPrecision 3650 Mt Firmware Version < 1.2.0
   DellPrecision 3650 Mt Version-
DellPrecision 5550 Firmware Version < 1.8.1
   DellPrecision 5550 Version-
DellPrecision 5560 Firmware Version < 1.3.2
   DellPrecision 5560 Version-
DellPrecision 5760 Firmware Version < 1.1.3
   DellPrecision 5760 Version-
DellPrecision 7550 Firmware Version < 1.8.0
   DellPrecision 7550 Version-
DellPrecision 7560 Firmware Version < 1.1.2
   DellPrecision 7560 Version-
DellPrecision 7750 Firmware Version < 1.8.0
   DellPrecision 7750 Version-
DellPrecision 7760 Firmware Version < 1.1.2
   DellPrecision 7760 Version-
DellVostro 14 5410 Firmware Version < 2.1.0_a06
   DellVostro 14 5410 Version-
DellVostro 15 5510 Firmware Version < 2.1.0_a06
   DellVostro 15 5510 Version-
DellVostro 15 7510 Firmware Version < 1.0.4
   DellVostro 15 7510 Version-
DellVostro 3400 Firmware Version < 1.6.0
   DellVostro 3400 Version-
DellVostro 3500 Firmware Version < 1.6.0
   DellVostro 3500 Version-
DellVostro 3501 Firmware Version < 1.6.0
   DellVostro 3501 Version-
DellVostro 3681 Firmware Version < 2.4.0
   DellVostro 3681 Version-
DellVostro 3690 Firmware Version < 1.0.11
   DellVostro 3690 Version-
DellVostro 3881 Firmware Version < 2.4.0
   DellVostro 3881 Version-
DellVostro 3888 Firmware Version < 2.4.0
   DellVostro 3888 Version-
DellVostro 3890 Firmware Version < 1.0.11
   DellVostro 3890 Version-
DellVostro 5300 Firmware Version < 1.7.1
   DellVostro 5300 Version-
DellVostro 5301 Firmware Version < 1.8.1
   DellVostro 5301 Version-
DellVostro 5310 Firmware Version < 2.1.0
   DellVostro 5310 Version-
DellVostro 5401 Firmware Version < 1.7.2
   DellVostro 5401 Version-
DellVostro 5402 Firmware Version < 1.5.1
   DellVostro 5402 Version-
DellVostro 5501 Firmware Version < 1.7.2
   DellVostro 5501 Version-
DellVostro 5502 Firmware Version < 1.5.1
   DellVostro 5502 Version-
DellVostro 5880 Firmware Version < 1.4.0
   DellVostro 5880 Version-
DellVostro 5890 Firmware Version < 1.0.11
   DellVostro 5890 Version-
DellVostro 7500 Firmware Version < 1.8.0
   DellVostro 7500 Version-
DellXps 13 9305 Firmware Version < 1.0.8
   DellXps 13 9305 Version-
DellXps 13 2in1 9310 Firmware Version < 2.3.3
   DellXps 13 2in1 9310 Version-
DellXps 13 9310 Firmware Version < 3.0.0
   DellXps 13 9310 Version-
DellXps 15 9500 Firmware Version < 1.8.1
   DellXps 15 9500 Version-
DellXps 15 9510 Firmware Version < 1.3.2
   DellXps 15 9510 Version-
DellXps 17 9700 Firmware Version < 1.8.2
   DellXps 17 9700 Version-
DellXps 17 9710 Firmware Version < 1.1.3
   DellXps 17 9710 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.08
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
security_alert@emc.com 7.2 0.6 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.