HIGH · 7.2

CVE-2021-21573

Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary cod...

Vulnerability Description

Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DellAlienware M15 R6 Firmware< 1.3.3
DellAlienware M15 R6-
DellChengming 3990 Firmware< 1.4.1
DellChengming 3990-
DellChengming 3991 Firmware< 1.4.1
DellChengming 3991-
DellG15 5510 Firmware< 1.4.0
DellG15 5510-
DellG15 5511 Firmware< 1.3.3
DellG15 5511-
DellG3 3500 Firmware<= 1.9.0
DellG3 3500-
DellG5 5500 Firmware< 1.9.0
DellG5 5500-
DellG7 7500 Firmware< 1.9.0
DellG7 7500-
DellG7 7700 Firmware< 1.9.0
DellG7 7700-
DellInspiron 14 5418 Firmware< 2.1.0_a06
DellInspiron 14 5418-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-21573?

CVE-2021-21573 is a vulnerability with a CVSS score of 7.2 (HIGH). Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary cod...

How severe is CVE-2021-21573?

CVE-2021-21573 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-21573?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Alienware M15 R6 Firmware, Dell Alienware M15 R6, Dell Chengming 3990 Firmware, Dell Chengming 3990, Dell Chengming 3991 Firmware.