CVE-2021-21571
Last modified
CVE-2021-21571 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Alienware M15 R6 Firmware | < 1.3.3 |
| Dell | Chengming 3990 Firmware | < 1.4.1 |
| Dell | Chengming 3991 Firmware | < 1.4.1 |
| Dell | G15 5510 Firmware | < 1.4.0 |
| Dell | G15 5511 Firmware | < 1.3.3 |
| Dell | G3 3500 Firmware | < 1.9.0 |
| Dell | G5 5500 Firmware | < 1.9.0 |
| Dell | G7 7500 Firmware | < 1.9.0 |
| Dell | G7 7700 Firmware | < 1.9.0 |
| Dell | Inspiron 14 5418 Firmware | < 2.1.0_a06 |
| Dell | Inspiron 15 5518 Firmware | < 2.1.0_a06 |
| Dell | Inspiron 15 7510 Firmware | < 1.0.4 |
| Dell | Inspiron 3501 Firmware | < 1.6.0 |
| Dell | Inspiron 3880 Firmware | < 1.4.1 |
| Dell | Inspiron 3881 Firmware | < 1.4.1 |
| Dell | Inspiron 3891 Firmware | < 1.0.11 |
| Dell | Inspiron 5300 Firmware | < 1.7.1 |
| Dell | Inspiron 5301 Firmware | < 1.8.1 |
| Dell | Inspiron 5310 Firmware | < 2.1.0 |
| Dell | Inspiron 5400 2-In-1 Firmware | < 1.7.0 |
| Dell | Inspiron 5400 Aio Firmware | < 1.4.0 |
| Dell | Inspiron 5401 Firmware | < 1.7.2 |
| Dell | Inspiron 5401 Aio Firmware | < 1.4.0 |
| Dell | Inspiron 5402 Firmware | < 1.5.1 |
| Dell | Inspiron 5406 2n1 Firmware | < 1.5.1 |
| Dell | Inspiron 5408 Firmware | < 1.7.2 |
| Dell | Inspiron 5409 Firmware | < 1.5.1 |
| Dell | Inspiron 5410 2-In-1 Firmware | < 2.1.0 |
| Dell | Inspiron 5501 Firmware | < 1.7.2 |
| Dell | Inspiron 5502 Firmware | < 1.5.1 |
| Dell | Inspiron 5508 Firmware | < 1.7.2 |
| Dell | Inspiron 5509 Firmware | < 1.5.1 |
| Dell | Inspiron 7300 Firmware | < 1.8.1 |
| Dell | Inspiron 7300 2-In-1 Firmware | < 1.3.0 |
| Dell | Inspiron 7306 2-In-1 Firmware | < 1.5.1 |
| Dell | Inspiron 7400 Firmware | < 1.8.1 |
| Dell | Inspiron 7500 Firmware | < 1.8.0 |
| Dell | Inspiron 7500 2-In-1 Firmware | < 1.3.0 |
| Dell | Inspiron 7501 Firmware | < 1.8.0 |
| Dell | Inspiron 7506 Firmware | < 1.5.1 |
| Dell | Inspiron 7610 Firmware | < 1.0.4 |
| Dell | Inspiron 7700 Aio Firmware | < 1.4.0 |
| Dell | Inspiron 7706 2-In-1 Firmware | < 1.5.1 |
| Dell | Latitude 3120 Firmware | < 1.1.0 |
| Dell | Latitude 3320 Firmware | < 1.4.0 |
| Dell | Latitude 3410 Firmware | < 1.9.0 |
| Dell | Latitude 3420 Firmware | < 1.8.0 |
| Dell | Latitude 3510 Firmware | < 1.9.0 |
| Dell | Latitude 3520 Firmware | < 1.8.0 |
| Dell | Latitude 5310 Firmware | < 1.7.0 |
Showing 50 of 128 affected configurations. See NVD for the full list.
References
- https://www.dell.com/support/kbdoc/en-us/000188682Vendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000188682Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-21571?
How severe is CVE-2021-21571?
How do I fix CVE-2021-21571?
Are you affected by CVE-2021-21571?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
