7.5

CVE-2021-36283

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

Data is provided by the National Vulnerability Database (NVD)
DellChengming 3990 Firmware Version < 1.3.1
   DellChengming 3990 Version-
DellChengming 3991 Firmware Version < 1.3.1
   DellChengming 3991 Version-
DellG3 15 3500 Firmware Version < 1.7.1
   DellG3 15 3500 Version-
DellG3 15 3590 Firmware Version < 1.12.0
   DellG3 15 3590 Version-
DellG3 15 5500 Firmware Version < 1.7.1
   DellG3 15 5500 Version-
DellInspiron 3493 Firmware Version < 1.12.0
   DellInspiron 3493 Version-
DellInspiron 3501 Firmware Version < 1.1.0
   DellInspiron 3501 Version-
DellInspiron 3593 Firmware Version < 1.12.0
   DellInspiron 3593 Version-
DellInspiron 3793 Firmware Version < 1.12.0
   DellInspiron 3793 Version-
DellInspiron 3880 Firmware Version < 1.3.1
   DellInspiron 3880 Version-
DellInspiron 3881 Firmware Version < 1.3.1
   DellInspiron 3881 Version-
DellInspiron 5400 2-in-1 Firmware Version < 1.5.0
   DellInspiron 5400 2-in-1 Version-
DellInspiron 5490 Firmware Version < 1.12.0
   DellInspiron 5490 Version-
DellInspiron 5493 Firmware Version < 1.12.0
   DellInspiron 5493 Version-
DellInspiron 5498 Firmware Version < 1.12.0
   DellInspiron 5498 Version-
DellInspiron 5590 Firmware Version < 1.12.0
   DellInspiron 5590 Version-
DellInspiron 5593 Firmware Version < 1.12.0
   DellInspiron 5593 Version-
DellInspiron 5598 Firmware Version < 1.12.0
   DellInspiron 5598 Version-
DellInspiron 7391 2-in-1 Firmware Version < 1.9.1
   DellInspiron 7391 2-in-1 Version-
DellInspiron 7500 Firmware Version < 1.5.1
   DellInspiron 7500 Version-
DellInspiron 7501 Firmware Version < 1.5.1
   DellInspiron 7501 Version-
DellInspiron 7590 Firmware Version < 1.8.0
   DellInspiron 7590 Version-
DellInspiron 7591 Firmware Version < 1.8.0
   DellInspiron 7591 Version-
DellLatitude 3310 Firmware Version < 1.8.3
   DellLatitude 3310 Version-
DellLatitude 3310 2-in-1 Firmware Version < 1.17.1
   DellLatitude 3310 2-in-1 Version-
DellLatitude 5300 Firmware Version < 1.12.1
   DellLatitude 5300 Version-
DellLatitude 5300 2-in-1 Firmware Version < 1.12.1
   DellLatitude 5300 2-in-1 Version-
DellLatitude 5310 Firmware Version < 1.4.2
   DellLatitude 5310 Version-
DellLatitude 5310 2 In 1 Firmware Version1.4.2
   DellLatitude 5310 2 In 1 Version-
DellLatitude 5400 Firmware Version < 1.10.1
   DellLatitude 5400 Version-
DellLatitude 5401 Firmware Version < 1.11.1
   DellLatitude 5401 Version-
DellLatitude 5410 Firmware Version < 1.4.3
   DellLatitude 5410 Version-
DellLatitude 5411 Firmware Version < 1.4.3
   DellLatitude 5411 Version-
DellLatitude 5500 Firmware Version < 1.10.1
   DellLatitude 5500 Version-
DellLatitude 5511 Firmware Version < 1.4.3
   DellLatitude 5511 Version-
DellLatitude 7200 2 In 1 Firmware Version < 1.10.1
   DellLatitude 7200 2 In 1 Version-
DellLatitude 7210 2 In 1 Firmware Version < 1.5.1
   DellLatitude 7210 2 In 1 Version-
DellLatitude 7300 Firmware Version < 1.11.1
   DellLatitude 7300 Version-
DellLatitude 7310 Firmware Version < 1.5.1
   DellLatitude 7310 Version-
DellLatitude 7400 Firmware Version < 1.11.1
   DellLatitude 7400 Version-
DellLatitude 7400 2-in-1 Firmware Version < 1.10.0
   DellLatitude 7400 2-in-1 Version-
DellLatitude 7410 Firmware Version < 1.5.1
   DellLatitude 7410 Version-
DellLatitude 9410 Firmware Version < 1.5.1
   DellLatitude 9410 Version-
DellLatitude 9510 Firmware Version < 1.4.2
   DellLatitude 9510 Version-
DellOptiplex 3080 Firmware Version < 1.3.1
   DellOptiplex 3080 Version-
DellOptiplex 3280 Aio Firmware Version < 1.3.1
   DellOptiplex 3280 Aio Version-
DellOptiplex 5080 Firmware Version < 1.3.1
   DellOptiplex 5080 Version-
DellOptiplex 5480 Aio Firmware Version < 1.4.0
   DellOptiplex 5480 Aio Version-
DellOptiplex 7080 Firmware Version < 1.3.10
   DellOptiplex 7080 Version-
DellOptiplex 7480 Aio Firmware Version < 1.6.2
   DellOptiplex 7480 Aio Version-
DellOptiplex 7780 Aio Firmware Version < 1.6.2
   DellOptiplex 7780 Aio Version-
DellPrecision 3440 Firmware Version < 1.3.10
   DellPrecision 3440 Version-
DellPrecision 3540 Firmware Version < 1.10.1
   DellPrecision 3540 Version-
DellPrecision 3541 Firmware Version < 1.11.1
   DellPrecision 3541 Version-
DellPrecision 3550 Firmware Version < 1.4.3
   DellPrecision 3550 Version-
DellPrecision 3551 Firmware Version < 1.4.3
   DellPrecision 3551 Version-
DellPrecision 3640 Tower Firmware Version < 1.4.3
   DellPrecision 3640 Tower Version-
DellPrecision 5540 Firmware Version < 1.9.1
   DellPrecision 5540 Version-
DellPrecision 5550 Firmware Version < 1.6.1
   DellPrecision 5550 Version-
DellPrecision 5750 Firmware Version < 1.6.3
   DellPrecision 5750 Version-
DellPrecision 7540 Firmware Version < 1.11.2
   DellPrecision 7540 Version-
DellPrecision 7550 Firmware Version < 1.6.2
   DellPrecision 7550 Version-
DellPrecision 7740 Firmware Version < 1.11.2
   DellPrecision 7740 Version-
DellPrecision 7750 Firmware Version < 1.6.2
   DellPrecision 7750 Version-
DellVostro 3401 Firmware Version < 1.1.0
   DellVostro 3401 Version-
DellVostro 3491 Firmware Version < 1.12.0
   DellVostro 3491 Version-
DellVostro 3501 Firmware Version < 1.1.0
   DellVostro 3501 Version-
DellVostro 3591 Firmware Version < 1.12.0
   DellVostro 3591 Version-
DellVostro 3681 Firmware Version < 1.3.1
   DellVostro 3681 Version-
DellVostro 3881 Firmware Version < 1.3.1
   DellVostro 3881 Version-
DellVostro 3888 Firmware Version < 1.3.1
   DellVostro 3888 Version-
DellVostro 5490 Firmware Version < 1.12.0
   DellVostro 5490 Version-
DellVostro 5590 Firmware Version < 1.12.0
   DellVostro 5590 Version-
DellVostro 7500 Firmware Version < 1.5.1
   DellVostro 7500 Version-
DellVostro 7590 Firmware Version < 1.8.0
   DellVostro 7590 Version-
DellWyse 5470 Firmware Version < 1.6.0
   DellWyse 5470 Version-
DellXps 13 9300 Firmware Version < 1.4.1
   DellXps 13 9300 Version-
DellXps 13 9380 Firmware Version < 1.12.0
   DellXps 13 9380 Version-
DellXps 17 9700 Firmware Version < 1.6.3
   DellXps 17 9700 Version-
DellXps 7380 Firmware Version < 1.7.0
   DellXps 7380 Version-
DellXps 7590 Firmware Version < 1.9.1
   DellXps 7590 Version-
DellXps 7390 2-in-1 Firmware Version < 1.7.1
DellXps 9500 Firmware Version < 1.6.1
   DellXps 9500
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.088
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
security_alert@emc.com 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.