Vulnerability Description
Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management Mode.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Poweredge R640 Firmware | < 2.11.2 |
| Dell | Poweredge R640 | - |
| Dell | Poweredge R740 Firmware | < 2.11.2 |
| Dell | Poweredge R740 | - |
| Dell | Poweredge R740Xd Firmware | < 2.11.2 |
| Dell | Poweredge R740Xd | - |
| Dell | Poweredge R940 Firmware | < 2.11.2 |
| Dell | Poweredge R940 | - |
| Dell | Poweredge R540 Firmware | < 2.11.2 |
| Dell | Poweredge R540 | - |
| Dell | Poweredge R440 Firmware | < 2.11.2 |
| Dell | Poweredge R440 | - |
| Dell | Poweredge T440 Firmware | < 2.11.2 |
| Dell | Poweredge T440 | - |
| Dell | Poweredge Xr2 Firmware | < 2.11.2 |
| Dell | Poweredge Xr2 | - |
| Dell | Poweredge R740Xd2 Firmware | < 2.11.2 |
| Dell | Poweredge R740Xd2 | - |
| Dell | Poweredge R840 Firmware | < 2.11.2 |
| Dell | Poweredge R840 | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/000187958PatchVendor Advisory
- https://www.dell.com/support/kbdoc/000187958PatchVendor Advisory
FAQ
What is CVE-2021-21557?
CVE-2021-21557 is a vulnerability with a CVSS score of 8.1 (HIGH). Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerabili...
How severe is CVE-2021-21557?
CVE-2021-21557 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21557?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Poweredge R640 Firmware, Dell Poweredge R640, Dell Poweredge R740 Firmware, Dell Poweredge R740, Dell Poweredge R740Xd Firmware.