60
CVE-2021-21571
—CVSS 3.1
6.5 medium
EPSS
<1%p44
Published
()
Modified
Description
Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.
- Vendors
- dell
- Products
- alienware m15 r6 firmware, chengming 3990 firmware, chengming 3991 firmware, g15 5510 firmware, g15 5511 firmware, g3 3500 firmware, g5 5500 firmware, g7 7500 firmware, g7 7700 firmware, inspiron 14 5418 firmware, inspiron 15 5518 firmware, inspiron 15 7510 firmware
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H