60
CVE-2021-21573
—CVSS 3.1
7.5 high
EPSS
<1%p20
Published
()
Modified
Description
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.
- Vendors
- dell
- Products
- alienware m15 r6 firmware, chengming 3990 firmware, chengming 3991 firmware, g15 5510 firmware, g15 5511 firmware, g3 3500 firmware, g5 5500 firmware, g7 7500 firmware, g7 7700 firmware, inspiron 14 5418 firmware, inspiron 15 5518 firmware, inspiron 15 7510 firmware
- Weakness
- CWE-121, CWE-787
- Vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H