Lucene search

K
cveDellCVE-2021-21522
HistorySep 28, 2021 - 8:15 p.m.

CVE-2021-21522

2021-09-2820:15:07
CWE-255
dell
web.nvd.nist.gov
22
dell
bios
credentials management
cve-2021-21522
nvme
vulnerability
manageability interface

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

4.6

Confidence

High

EPSS

0

Percentile

5.1%

Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.

Affected configurations

Nvd
Vulners
Node
delllatitude_5285_2-in-1_firmwareRange<1.13.0
AND
delllatitude_5285_2-in-1
Node
delllatitude_5289_2-in-1_firmwareRange<1.23.1
AND
delllatitude_5289_2-in-1
Node
delllatitude_5310_2-in-1_firmwareMatch1.7.0
AND
delllatitude_5310_2-in-1
Node
delllatitude_5290_2-in-1_firmwareRange<1.16.0
AND
delllatitude_5290_2-in-1
Node
delllatitude_7210_2-in-1_firmwareRange<1.7.0
AND
delllatitude_7210_2-in-1Match-
Node
delllatitude_7212_rugged_extreme_tablet_firmwareRange<1.33.0
OR
delllatitude_7212_rugged_extreme_tablet_firmwareMatch1.33.0
AND
delllatitude_7212_rugged_extreme_tabletMatch-
Node
delllatitude_7280_firmwareRange<1.21.1
OR
delllatitude_7280_firmwareMatch1.21.1
AND
delllatitude_7280Match-
Node
delllatitude_7290_firmwareRange<1.20.0
OR
delllatitude_7290_firmwareMatch1.20.0
AND
delllatitude_7290Match-
Node
delllatitude_7285_firmwareRange<1.11.0
OR
delllatitude_7285_firmwareMatch1.11.0
AND
delllatitude_7285Match-
Node
delllatitude_7370_firmwareRange<1.24.3
OR
delllatitude_7370_firmwareMatch1.24.3
AND
delllatitude_7370Match-
Node
delllatitude_7310_firmwareRange<1.7.0
AND
delllatitude_7310Match-
Node
delllatitude_7380_firmwareMatch1.21.1
AND
delllatitude_7380Match-
Node
delllatitude_7389_firmwareRange<1.23.1
AND
delllatitude_7389Match-
Node
delllatitude_7390_firmwareMatch1.20.0
AND
delllatitude_7390Match-
Node
delllatitude_7410_firmwareRange<1.7.0
AND
delllatitude_7410Match-
Node
delllatitude_7390_2-in-1_firmwareRange<1.19.0
AND
delllatitude_7390_2-in-1Match-
Node
delllatitude_7420_firmwareRange<1.7.1
AND
delllatitude_7420Match-
Node
delllatitude_7480_firmwareRange<1.21.1
AND
delllatitude_7480Match-
Node
delllatitude_7490_firmwareRange<1.20.1
AND
delllatitude_7490Match-
Node
delllatitude_9410_firmwareRange<1.7.0
AND
delllatitude_9410Match-
Node
delllatitude_9510_firmwareRange<1.6.0
AND
delllatitude_9510Match-
Node
dellprecision_3640_tower_firmwareRange<1.6.2
AND
dellprecision_3640_towerMatch-
Node
dellprecision_5520_firmwareRange<1.23.1
AND
dellprecision_5520Match-
Node
dellprecision_5510_firmwareRange<1.17.0
AND
dellprecision_5510Match-
Node
dellprecision_5530_2-in-1_firmwareRange<1.14.10
AND
dellprecision_5530_2-in-1Match-
Node
dellxps_13_9360_firmwareRange<2.16.0
AND
dellxps_13_9360Match-
Node
dellxps_13_9370_firmwareRange<1.15.0
AND
dellxps_13_9370Match-
Node
dellxps_15_9575_2-in-1_firmwareRange<1.16.2
AND
dellxps_15_9575_2-in-1Match-
VendorProductVersionCPE
delllatitude_5285_2-in-1_firmware*cpe:2.3:o:dell:latitude_5285_2-in-1_firmware:*:*:*:*:*:*:*:*
delllatitude_5285_2-in-1*cpe:2.3:h:dell:latitude_5285_2-in-1:*:*:*:*:*:*:*:*
delllatitude_5289_2-in-1_firmware*cpe:2.3:o:dell:latitude_5289_2-in-1_firmware:*:*:*:*:*:*:*:*
delllatitude_5289_2-in-1*cpe:2.3:h:dell:latitude_5289_2-in-1:*:*:*:*:*:*:*:*
delllatitude_5310_2-in-1_firmware1.7.0cpe:2.3:o:dell:latitude_5310_2-in-1_firmware:1.7.0:*:*:*:*:*:*:*
delllatitude_5310_2-in-1*cpe:2.3:h:dell:latitude_5310_2-in-1:*:*:*:*:*:*:*:*
delllatitude_5290_2-in-1_firmware*cpe:2.3:o:dell:latitude_5290_2-in-1_firmware:*:*:*:*:*:*:*:*
delllatitude_5290_2-in-1*cpe:2.3:h:dell:latitude_5290_2-in-1:*:*:*:*:*:*:*:*
delllatitude_7210_2-in-1_firmware*cpe:2.3:o:dell:latitude_7210_2-in-1_firmware:*:*:*:*:*:*:*:*
delllatitude_7210_2-in-1-cpe:2.3:h:dell:latitude_7210_2-in-1:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 611

CNA Affected

[
  {
    "product": "CPG BIOS",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "1.13.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

4.6

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2021-21522