MEDIUM · 5.9

CVE-2021-21571

Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploi...

Vulnerability Description

Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
DellAlienware M15 R6 Firmware< 1.3.3
DellAlienware M15 R6-
DellChengming 3990 Firmware< 1.4.1
DellChengming 3990-
DellChengming 3991 Firmware< 1.4.1
DellChengming 3991-
DellG15 5510 Firmware< 1.4.0
DellG15 5510-
DellG15 5511 Firmware< 1.3.3
DellG15 5511-
DellG3 3500 Firmware< 1.9.0
DellG3 3500-
DellG5 5500 Firmware< 1.9.0
DellG5 5500-
DellG7 7500 Firmware< 1.9.0
DellG7 7500-
DellG7 7700 Firmware< 1.9.0
DellG7 7700-
DellInspiron 14 5418 Firmware< 2.1.0_a06
DellInspiron 14 5418-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-21571?

CVE-2021-21571 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploi...

How severe is CVE-2021-21571?

CVE-2021-21571 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-21571?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Alienware M15 R6 Firmware, Dell Alienware M15 R6, Dell Chengming 3990 Firmware, Dell Chengming 3990, Dell Chengming 3991 Firmware.