Vulnerability Description
Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and, Dell Precision 7920 Rack Workstation BIOS contain a stack-based buffer overflow vulnerability in systems with Intel Optane DC Persistent Memory installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Poweredge R640 Firmware | < 2.9.4 |
| Dell | Poweredge R640 | - |
| Dell | Poweredge R740 Firmware | < 2.9.4 |
| Dell | Poweredge R740 | - |
| Dell | Poweredge R740Xd Firmware | < 2.9.4 |
| Dell | Poweredge R740Xd | - |
| Dell | Poweredge R940 Firmware | < 2.9.4 |
| Dell | Poweredge R940 | - |
| Dell | Poweredge R840 Firmware | < 2.9.4 |
| Dell | Poweredge R840 | - |
| Dell | Poweredge R940Xa Firmware | < 2.9.4 |
| Dell | Poweredge R940Xa | - |
| Dell | Poweredge Mx740C Firmware | < 2.9.4 |
| Dell | Poweredge Mx740C | - |
| Dell | Poweredge Mx840C Firmware | < 2.9.4 |
| Dell | Poweredge Mx840C | - |
| Dell | Precision 7920 Firmware | - |
| Dell | Precision 7920 | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/000187958PatchVendor Advisory
- https://www.dell.com/support/kbdoc/000187958PatchVendor Advisory
FAQ
What is CVE-2021-21554?
CVE-2021-21554 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and, Dell Precision 7920 Rack Workstation BIOS contain a stack-based buffer overflow vulnerability in systems with Intel Optane D...
How severe is CVE-2021-21554?
CVE-2021-21554 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21554?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Poweredge R640 Firmware, Dell Poweredge R640, Dell Poweredge R740 Firmware, Dell Poweredge R740, Dell Poweredge R740Xd Firmware.