ZeroHour

CVE-2021-21571

CVSS 3.1
6.5 medium
EPSS
<1%p44
Published
()
Modified
Description

Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.

Vendors
dell
Products
alienware m15 r6 firmware, chengming 3990 firmware, chengming 3991 firmware, g15 5510 firmware, g15 5511 firmware, g3 3500 firmware, g5 5500 firmware, g7 7500 firmware, g7 7700 firmware, inspiron 14 5418 firmware, inspiron 15 5518 firmware, inspiron 15 7510 firmware
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

In the news