CVE-2021-21522

MEDIUMCVSS 4.4/10EPSS 0.23%

Last modified

CVE-2021-21522 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.

Description

Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.

Metrics

CVSS 3.1
4.4/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.23%

13.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellLatitude 5285 2-In-1 Firmware< 1.13.0
DellLatitude 5289 2-In-1 Firmware< 1.23.1
DellLatitude 5310 2-In-1 Firmware1.7.0
DellLatitude 5290 2-In-1 Firmware< 1.16.0
DellLatitude 7210 2-In-1 Firmware< 1.7.0
DellLatitude 7212 Rugged Extreme Tablet Firmware< 1.33.0
DellLatitude 7212 Rugged Extreme Tablet Firmware1.33.0
DellLatitude 7280 Firmware< 1.21.1
DellLatitude 7280 Firmware1.21.1
DellLatitude 7290 Firmware< 1.20.0
DellLatitude 7290 Firmware1.20.0
DellLatitude 7285 Firmware< 1.11.0
DellLatitude 7285 Firmware1.11.0
DellLatitude 7370 Firmware< 1.24.3
DellLatitude 7370 Firmware1.24.3
DellLatitude 7310 Firmware< 1.7.0
DellLatitude 7380 Firmware1.21.1
DellLatitude 7389 Firmware< 1.23.1
DellLatitude 7390 Firmware1.20.0
DellLatitude 7410 Firmware< 1.7.0
DellLatitude 7390 2-In-1 Firmware< 1.19.0
DellLatitude 7420 Firmware< 1.7.1
DellLatitude 7480 Firmware< 1.21.1
DellLatitude 7490 Firmware< 1.20.1
DellLatitude 9410 Firmware< 1.7.0
DellLatitude 9510 Firmware< 1.6.0
DellPrecision 3640 Tower Firmware< 1.6.2
DellPrecision 5520 Firmware< 1.23.1
DellPrecision 5510 Firmware< 1.17.0
DellPrecision 5530 2-In-1 Firmware< 1.14.10
DellXps 13 9360 Firmware< 2.16.0
DellXps 13 9370 Firmware< 1.15.0
DellXps 15 9575 2-In-1 Firmware< 1.16.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-21522?
Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.
How severe is CVE-2021-21522?
CVE-2021-21522 has a CVSS score of 4.4/10 (MEDIUM severity). The EPSS model estimates a 0.23% probability of exploitation in the next 30 days.
How do I fix CVE-2021-21522?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-21522?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST