CVE-2021-21573

HIGHCVSS 7.5/10EPSS 0.28%

Last modified

CVE-2021-21573 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.

Description

Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS Probability
0.28%

19.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellAlienware M15 R6 Firmware< 1.3.3
DellChengming 3990 Firmware< 1.4.1
DellChengming 3991 Firmware< 1.4.1
DellG15 5510 Firmware< 1.4.0
DellG15 5511 Firmware< 1.3.3
DellG3 3500 Firmware<= 1.9.0
DellG5 5500 Firmware< 1.9.0
DellG7 7500 Firmware< 1.9.0
DellG7 7700 Firmware< 1.9.0
DellInspiron 14 5418 Firmware< 2.1.0_a06
DellInspiron 15 5518 Firmware< 2.1.0_a06
DellInspiron 15 7510 Firmware< 1.0.4
DellInspiron 3501 Firmware< 1.6.0
DellInspiron 3880 Firmware< 1.4.1
DellInspiron 3881 Firmware< 1.4.1
DellInspiron 3891 Firmware< 1.0.11
DellInspiron 5300 Firmware< 1.7.1
DellInspiron 5301 Firmware< 1.8.1
DellInspiron 5310 Firmware< 2.1.0
DellInspiron 5400 2-In-1 Firmware< 1.7.0
DellInspiron 5400 Aio Firmware< 1.4.0
DellInspiron 5401 Firmware< 1.7.2
DellInspiron 5401 Aio Firmware< 1.4.0
DellInspiron 5402 Firmware< 1.5.1
DellInspiron 5406 2n1 Firmware< 1.5.1
DellInspiron 5408 Firmware< 1.7.2
DellInspiron 5409 Firmware< 1.5.1
DellInspiron 5410 2-In-1 Firmware< 2.1.0
DellInspiron 5501 Firmware< 1.7.2
DellInspiron 5502 Firmware< 1.5.1
DellInspiron 5508 Firmware< 1.7.2
DellInspiron 5509 Firmware< 1.5.1
DellInspiron 7300 Firmware< 1.8.1
DellInspiron 7300 2-In-1 Firmware< 1.3.0
DellInspiron 7306 2-In-1 Firmware< 1.5.1
DellInspiron 7400 Firmware< 1.8.1
DellInspiron 7500 Firmware< 1.8.0
DellInspiron 7500 2-In-1 Firmware< 1.3.0
DellInspiron 7501 Firmware< 1.8.0
DellInspiron 7506 Firmware< 1.5.1
DellInspiron 7610 Firmware< 1.0.4
DellInspiron 7700 Aio Firmware< 1.4.0
DellInspiron 7706 2-In-1 Firmware< 1.5.1
DellLatitude 3120 Firmware< 1.1.0
DellLatitude 3320 Firmware< 1.4.0
DellLatitude 3410 Firmware< 1.9.0
DellLatitude 3420 Firmware< 1.8.0
DellLatitude 3510 Firmware< 1.9.0
DellLatitude 3520 Firmware< 1.8.0
DellLatitude 5310 Firmware< 1.7.0

Showing 50 of 128 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-21573?
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.
How severe is CVE-2021-21573?
CVE-2021-21573 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.28% probability of exploitation in the next 30 days.
How do I fix CVE-2021-21573?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-21573?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST