CVE-2021-36343

MEDIUMCVSS 6.4/10EPSS 0.24%

Last modified

CVE-2021-36343 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.

Description

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

Metrics

CVSS 3.1
6.4/10

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.24%

15.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellPrecision 5820 Tower Firmware< 2.12.1
DellPrecision 7510 Firmware< 1.24.3
DellPrecision 7520 Firmware< 1.22.0
DellPrecision 7530 Firmware< 1.18.2
DellPrecision 7540 Firmware< 1.15.1
DellPrecision 7550 Firmware< 1.10.1
DellPrecision 7560 Firmware< 1.5.0
DellPrecision 7710 Firmware< 1.24.3
DellPrecision 7720 Firmware< 1.22.0
DellPrecision 7730 Firmware< 1.18.2
DellPrecision 7740 Firmware< 1.15.1
DellPrecision 7750 Firmware< 1.10.1
DellPrecision 7760 Firmware< 1.5.0
DellVostro 13 5370 Firmware< 1.20.0
DellVostro 14 3468 Firmware< 3.10.0
DellVostro 14 3478 Firmware< 1.15.0
DellVostro 14 5468 Firmware< 1.17.0
DellVostro 14 5471 Firmware< 1.20.0
DellVostro 15 3568 Firmware< 3.10.0
DellVostro 15 3572 Firmware< 1.12.0
DellVostro 15 3578 Firmware< 1.15.0
DellVostro 15 5410 Firmware< 2.4.1
DellVostro 15 5510 Firmware< 2.4.1
DellVostro 15 5568 Firmware< 1.17.0
DellVostro 15 7570 Firmware< 1.15.0
DellVostro 15 7580 Firmware< 1.18.0
DellVostro 3070 Firmware< 2.20.0
DellVostro 3267 Firmware< 1.18.0
DellVostro 3268 Firmware< 1.18.0
DellVostro 3400 Firmware< 1.9.0
DellVostro 3401 Firmware< 1.9.0
DellVostro 3470 Firmware< 2.20.0
DellVostro 3471 Firmware< 1.8.0
DellVostro 3480 Firmware< 1.16.0
DellVostro 3481 Firmware< 1.15.0
DellVostro 3490 Firmware< 1.15.0
DellVostro 3500 Firmware< 1.9.0
DellVostro 3501 Firmware< 1.9.0
DellVostro 3510 Firmware< 1.6.0
DellVostro 3562 Firmware< 1.19.0
DellVostro 3580 Firmware< 1.16.0
DellVostro 3581 Firmware< 1.15.0
DellVostro 3582 Firmware< 1.11.0
DellVostro 3583 Firmware< 1.16.0
DellVostro 3584 Firmware< 1.15.0
DellVostro 3590 Firmware< 1.15.0
DellVostro 3660 Firmware< 1.18.0
DellVostro 3667 Firmware< 1.18.0
DellVostro 3668 Firmware< 1.18.0
DellVostro 3669 Firmware< 1.18.0

Showing 50 of 414 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2021-36343?
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
How severe is CVE-2021-36343?
CVE-2021-36343 has a CVSS score of 6.4/10 (MEDIUM severity). The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2021-36343?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-36343?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST