Lucene search

K
nvd[email protected]NVD:CVE-2021-21554
HistoryJun 14, 2021 - 7:15 p.m.

CVE-2021-21554

2021-06-1419:15:08
CWE-122
CWE-787
web.nvd.nist.gov
1
dell poweredge
r640
r740
r740xd
r840
r940
r940xa
mx740c
mx840c
precision 7920 rack workstation
stack-based buffer overflow
intel optane dc persistent memory
denial of service
arbitrary code execution
information disclosure
uefi
bios preboot environment

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and, Dell Precision 7920 Rack Workstation BIOS contain a stack-based buffer overflow vulnerability in systems with Intel Optane DC Persistent Memory installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.

Affected configurations

Nvd
Node
dellpoweredge_r640_firmwareRange<2.9.4
AND
dellpoweredge_r640Match-
Node
dellpoweredge_r740_firmwareRange<2.9.4
AND
dellpoweredge_r740Match-
Node
dellpoweredge_r740xd_firmwareRange<2.9.4
AND
dellpoweredge_r740xdMatch-
Node
dellpoweredge_r940_firmwareRange<2.9.4
AND
dellpoweredge_r940Match-
Node
dellpoweredge_r840_firmwareRange<2.9.4
AND
dellpoweredge_r840Match-
Node
dellpoweredge_r940xa_firmwareRange<2.9.4
AND
dellpoweredge_r940xaMatch-
Node
dellpoweredge_mx740c_firmwareRange<2.9.4
AND
dellpoweredge_mx740cMatch-
Node
dellpoweredge_mx840c_firmwareRange<2.9.4
AND
dellpoweredge_mx840cMatch-
Node
dellprecision_7920_firmwareMatch-
AND
dellprecision_7920Match-
VendorProductVersionCPE
dellpoweredge_r640_firmware*cpe:2.3:o:dell:poweredge_r640_firmware:*:*:*:*:*:*:*:*
dellpoweredge_r640-cpe:2.3:h:dell:poweredge_r640:-:*:*:*:*:*:*:*
dellpoweredge_r740_firmware*cpe:2.3:o:dell:poweredge_r740_firmware:*:*:*:*:*:*:*:*
dellpoweredge_r740-cpe:2.3:h:dell:poweredge_r740:-:*:*:*:*:*:*:*
dellpoweredge_r740xd_firmware*cpe:2.3:o:dell:poweredge_r740xd_firmware:*:*:*:*:*:*:*:*
dellpoweredge_r740xd-cpe:2.3:h:dell:poweredge_r740xd:-:*:*:*:*:*:*:*
dellpoweredge_r940_firmware*cpe:2.3:o:dell:poweredge_r940_firmware:*:*:*:*:*:*:*:*
dellpoweredge_r940-cpe:2.3:h:dell:poweredge_r940:-:*:*:*:*:*:*:*
dellpoweredge_r840_firmware*cpe:2.3:o:dell:poweredge_r840_firmware:*:*:*:*:*:*:*:*
dellpoweredge_r840-cpe:2.3:h:dell:poweredge_r840:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 181

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Related for NVD:CVE-2021-21554