Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-21574


Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.2, requiring local system access to exploit but requires specific conditions to be met though user interaction is required . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 256 products from dell, from dell, from dell and 253 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2021, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2021-06-24T17:15:08.013

Last Modified

2024-11-21T05:48:37.897

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.4

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-121
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dell alienware_m15_r6_firmware < 1.3.3 Yes
Hardware dell alienware_m15_r6 - No
Operating System dell chengming_3990_firmware < 1.4.1 Yes
Hardware dell chengming_3990 - No
Operating System dell chengming_3991_firmware < 1.4.1 Yes
Hardware dell chengming_3991 - No
Operating System dell g15_5510_firmware < 1.4.0 Yes
Hardware dell g15_5510 - No
Operating System dell g15_5511_firmware < 1.3.3 Yes
Hardware dell g15_5511 - No
Operating System dell g3_3500_firmware ≤ 1.9.0 Yes
Hardware dell g3_3500 - No
Operating System dell g5_5500_firmware < 1.9.0 Yes
Hardware dell g5_5500 - No
Operating System dell g7_7500_firmware < 1.9.0 Yes
Hardware dell g7_7500 - No
Operating System dell g7_7700_firmware < 1.9.0 Yes
Hardware dell g7_7700 - No
Operating System dell inspiron_14_5418_firmware < 2.1.0_a06 Yes
Hardware dell inspiron_14_5418 - No
Operating System dell inspiron_15_5518_firmware < 2.1.0_a06 Yes
Hardware dell inspiron_15_5518 - No
Operating System dell inspiron_15_7510_firmware < 1.0.4 Yes
Hardware dell inspiron_15_7510 - No
Operating System dell inspiron_3501_firmware < 1.6.0 Yes
Hardware dell inspiron_3501 - No
Operating System dell inspiron_3880_firmware < 1.4.1 Yes
Hardware dell inspiron_3880 - No
Operating System dell inspiron_3881_firmware < 1.4.1 Yes
Hardware dell inspiron_3881 - No
Operating System dell inspiron_3891_firmware < 1.0.11 Yes
Hardware dell inspiron_3891 - No
Operating System dell inspiron_5300_firmware < 1.7.1 Yes
Hardware dell inspiron_5300 - No
Operating System dell inspiron_5301_firmware < 1.8.1 Yes
Hardware dell inspiron_5301 - No
Operating System dell inspiron_5310_firmware < 2.1.0 Yes
Hardware dell inspiron_5310 - No
Operating System dell inspiron_5400_2-in-1_firmware < 1.7.0 Yes
Hardware dell inspiron_5400_2-in-1 - No
Operating System dell inspiron_5400_aio_firmware < 1.4.0 Yes
Hardware dell inspiron_5400_aio - No
Operating System dell inspiron_5401_firmware < 1.7.2 Yes
Hardware dell inspiron_5401 - No
Operating System dell inspiron_5401_aio_firmware < 1.4.0 Yes
Hardware dell inspiron_5401_aio - No
Operating System dell inspiron_5402_firmware < 1.5.1 Yes
Hardware dell inspiron_5402 - No
Operating System dell inspiron_5406_2n1_firmware < 1.5.1 Yes
Hardware dell inspiron_5406_2n1 - No
Operating System dell inspiron_5408_firmware < 1.7.2 Yes
Hardware dell inspiron_5408 - No
Operating System dell inspiron_5409_firmware < 1.5.1 Yes
Hardware dell inspiron_5409 - No
Operating System dell inspiron_5410_2-in-1_firmware < 2.1.0 Yes
Hardware dell inspiron_5410_2-in-1 - No
Operating System dell inspiron_5501_firmware < 1.7.2 Yes
Hardware dell inspiron_5501 - No
Operating System dell inspiron_5502_firmware < 1.5.1 Yes
Hardware dell inspiron_5502 - No
Operating System dell inspiron_5508_firmware < 1.7.2 Yes
Hardware dell inspiron_5508 - No
Operating System dell inspiron_5509_firmware < 1.5.1 Yes
Hardware dell inspiron_5509 - No
Operating System dell inspiron_7300_firmware < 1.8.1 Yes
Hardware dell inspiron_7300 - No
Operating System dell inspiron_7300_2-in-1_firmware < 1.3.0 Yes
Hardware dell inspiron_7300_2-in-1 - No
Operating System dell inspiron_7306_2-in-1_firmware < 1.5.1 Yes
Hardware dell inspiron_7306_2-in-1 - No
Operating System dell inspiron_7400_firmware < 1.8.1 Yes
Hardware dell inspiron_7400 - No
Operating System dell inspiron_7500_firmware < 1.8.0 Yes
Hardware dell inspiron_7500 - No
Operating System dell inspiron_7500_2-in-1_firmware < 1.3.0 Yes
Hardware dell inspiron_7500_2-in-1 - No
Operating System dell inspiron_7501_firmware < 1.8.0 Yes
Hardware dell inspiron_7501 - No
Operating System dell inspiron_7506_firmware < 1.5.1 Yes
Hardware dell inspiron_7506 - No
Operating System dell inspiron_7610_firmware < 1.0.4 Yes
Hardware dell inspiron_7610 - No
Operating System dell inspiron_7700_aio_firmware < 1.4.0 Yes
Hardware dell inspiron_7700_aio - No
Operating System dell inspiron_7706_2-in-1_firmware < 1.5.1 Yes
Hardware dell inspiron_7706_2-in-1 - No
Operating System dell latitude_3120_firmware < 1.1.0 Yes
Hardware dell latitude_3120 - No
Operating System dell latitude_3320_firmware < 1.4.0 Yes
Hardware dell latitude_3320 - No
Operating System dell latitude_3410_firmware < 1.9.0 Yes
Hardware dell latitude_3410 - No
Operating System dell latitude_3420_firmware < 1.8.0 Yes
Hardware dell latitude_3420 - No
Operating System dell latitude_3510_firmware < 1.9.0 Yes
Hardware dell latitude_3510 - No
Operating System dell latitude_3520_firmware < 1.8.0 Yes
Hardware dell latitude_3520 - No
Operating System dell latitude_5310_firmware < 1.7.0 Yes
Hardware dell latitude_5310 - No
Operating System dell latitude_5310_2-in-1_firmware < 1.7.0 Yes
Hardware dell latitude_5310_2-in-1 - No
Operating System dell latitude_5320_firmware < 1.7.1 Yes
Hardware dell latitude_5320 - No
Operating System dell latitude_5320_2-in-1_firmware < 1.7.1 Yes
Hardware dell latitude_5320_2-in-1 - No
Operating System dell latitude_5410_firmware < 1.6.0 Yes
Hardware dell latitude_5410 - No
Operating System dell latitude_5411_firmware < 1.6.0 Yes
Hardware dell latitude_5411 - No
Operating System dell latitude_5420_firmware < 1.8.0 Yes
Hardware dell latitude_5420 - No
Operating System dell latitude_5510_firmware < 1.6.0 Yes
Hardware dell latitude_5510 - No
Operating System dell latitude_5511_firmware < 1.6.0 Yes
Hardware dell latitude_5511 - No
Operating System dell latitude_5520_firmware < 1.7.1 Yes
Hardware dell latitude_5520 - No
Operating System dell latitude_5521_firmware < 1.3.0_a03 Yes
Hardware dell latitude_5521 - No
Operating System dell latitude_7210_2-in-1_firmware < 1.7.0 Yes
Hardware dell latitude_7210_2-in-1 - No
Operating System dell latitude_7310_firmware < 1.7.0 Yes
Hardware dell latitude_7310 - No
Operating System dell latitude_7320_firmware < 1.7.1 Yes
Hardware dell latitude_7320 - No
Operating System dell latitude_7320_detachable_firmware < 1.4.0_a04 Yes
Hardware dell latitude_7320_detachable - No
Operating System dell latitude_7410_firmware < 1.7.0 Yes
Hardware dell latitude_7410 - No
Operating System dell latitude_7420_firmware < 1.7.1 Yes
Hardware dell latitude_7420 - No
Operating System dell latitude_7520_firmware < 1.7.1 Yes
Hardware dell latitude_7520 - No
Operating System dell latitude_9410_firmware < 1.7.0 Yes
Hardware dell latitude_9410 - No
Operating System dell latitude_9420_firmware < 1.4.1 Yes
Hardware dell latitude_9420 - No
Operating System dell latitude_9510_firmware < 1.6.0 Yes
Hardware dell latitude_9510 - No
Operating System dell latitude_9520_firmware < 1.5.2 Yes
Hardware dell latitude_9520 - No
Operating System dell latitude_5421_firmware < 1.3.0_a03 Yes
Hardware dell latitude_5421 - No
Operating System dell optiplex_3080_firmware < 2.1.1 Yes
Hardware dell optiplex_3080 - No
Operating System dell optiplex_3090_uff_firmware < 1.2.0 Yes
Hardware dell optiplex_3090_uff - No
Operating System dell optiplex_3280_all-in-one_firmware < 1.7.0 Yes
Hardware dell optiplex_3280_all-in-one - No
Operating System dell optiplex_5080_firmware < 1.4.0 Yes
Hardware dell optiplex_5080 - No
Operating System dell optiplex_5090_tower_firmware < 1.1.35 Yes
Hardware dell optiplex_5090_tower - No
Operating System dell optiplex_5490_aio_firmware < 1.3.0 Yes
Hardware dell optiplex_5490_aio - No
Operating System dell optiplex_7080_firmware < 1.4.0 Yes
Hardware dell optiplex_7080 - No
Operating System dell optiplex_7090_tower_firmware < 1.1.35 Yes
Hardware dell optiplex_7090_tower - No
Operating System dell optiplex_7090_uff_firmware < 1.2.0 Yes
Hardware dell optiplex_7090_uff - No
Operating System dell optiplex_7480_all-in-one_firmware < 1.7.0 Yes
Hardware dell optiplex_7480_all-in-one - No
Operating System dell optiplex_7490_all-in-one_firmware < 1.3.0 Yes
Hardware dell optiplex_7490_all-in-one - No
Operating System dell optiplex_7780_all-in-one_firmware < 1.7.0 Yes
Hardware dell optiplex_7780_all-in-one - No
Operating System dell precision_17_m5750_firmware < 1.8.2 Yes
Hardware dell precision_17_m5750 - No
Operating System dell precision_3440_firmware < 1.4.0 Yes
Hardware dell precision_3440 - No
Operating System dell precision_3450_firmware < 1.1.35 Yes
Hardware dell precision_3450 - No
Operating System dell precision_3550_firmware < 1.6.0 Yes
Hardware dell precision_3550 - No
Operating System dell precision_3551_firmware < 1.6.0 Yes
Hardware dell precision_3551 - No
Operating System dell precision_3560_firmware < 1.7.1 Yes
Hardware dell precision_3560 - No
Operating System dell precision_3561_firmware < 1.3.0_a03 Yes
Hardware dell precision_3561 - No
Operating System dell precision_3640_firmware < 1.6.2 Yes
Hardware dell precision_3640 - No
Operating System dell precision_3650_mt_firmware < 1.2.0 Yes
Hardware dell precision_3650_mt - No
Operating System dell precision_5550_firmware < 1.8.1 Yes
Hardware dell precision_5550 - No
Operating System dell precision_5560_firmware < 1.3.2 Yes
Hardware dell precision_5560 - No
Operating System dell precision_5760_firmware < 1.1.3 Yes
Hardware dell precision_5760 - No
Operating System dell precision_7550_firmware < 1.8.0 Yes
Hardware dell precision_7550 - No
Operating System dell precision_7560_firmware < 1.1.2 Yes
Hardware dell precision_7560 - No
Operating System dell precision_7750_firmware < 1.8.0 Yes
Hardware dell precision_7750 - No
Operating System dell precision_7760_firmware < 1.1.2 Yes
Hardware dell precision_7760 - No
Operating System dell vostro_14_5410_firmware < 2.1.0_a06 Yes
Hardware dell vostro_14_5410 - No
Operating System dell vostro_15_5510_firmware < 2.1.0_a06 Yes
Hardware dell vostro_15_5510 - No
Operating System dell vostro_15_7510_firmware < 1.0.4 Yes
Hardware dell vostro_15_7510 - No
Operating System dell vostro_3400_firmware < 1.6.0 Yes
Hardware dell vostro_3400 - No
Operating System dell vostro_3500_firmware < 1.6.0 Yes
Hardware dell vostro_3500 - No
Operating System dell vostro_3501_firmware < 1.6.0 Yes
Hardware dell vostro_3501 - No
Operating System dell vostro_3681_firmware < 2.4.0 Yes
Hardware dell vostro_3681 - No
Operating System dell vostro_3690_firmware < 1.0.11 Yes
Hardware dell vostro_3690 - No
Operating System dell vostro_3881_firmware < 2.4.0 Yes
Hardware dell vostro_3881 - No
Operating System dell vostro_3888_firmware < 2.4.0 Yes
Hardware dell vostro_3888 - No
Operating System dell vostro_3890_firmware < 1.0.11 Yes
Hardware dell vostro_3890 - No
Operating System dell vostro_5300_firmware < 1.7.1 Yes
Hardware dell vostro_5300 - No
Operating System dell vostro_5301_firmware < 1.8.1 Yes
Hardware dell vostro_5301 - No
Operating System dell vostro_5310_firmware < 2.1.0 Yes
Hardware dell vostro_5310 - No
Operating System dell vostro_5401_firmware < 1.7.2 Yes
Hardware dell vostro_5401 - No
Operating System dell vostro_5402_firmware < 1.5.1 Yes
Hardware dell vostro_5402 - No
Operating System dell vostro_5501_firmware < 1.7.2 Yes
Hardware dell vostro_5501 - No
Operating System dell vostro_5502_firmware < 1.5.1 Yes
Hardware dell vostro_5502 - No
Operating System dell vostro_5880_firmware < 1.4.0 Yes
Hardware dell vostro_5880 - No
Operating System dell vostro_5890_firmware < 1.0.11 Yes
Hardware dell vostro_5890 - No
Operating System dell vostro_7500_firmware < 1.8.0 Yes
Hardware dell vostro_7500 - No
Operating System dell xps_13_9305_firmware < 1.0.8 Yes
Hardware dell xps_13_9305 - No
Operating System dell xps_13_2in1_9310_firmware < 2.3.3 Yes
Hardware dell xps_13_2in1_9310 - No
Operating System dell xps_13_9310_firmware < 3.0.0 Yes
Hardware dell xps_13_9310 - No
Operating System dell xps_15_9500_firmware < 1.8.1 Yes
Hardware dell xps_15_9500 - No
Operating System dell xps_15_9510_firmware < 1.3.2 Yes
Hardware dell xps_15_9510 - No
Operating System dell xps_17_9700_firmware < 1.8.2 Yes
Hardware dell xps_17_9700 - No
Operating System dell xps_17_9710_firmware < 1.1.3 Yes
Hardware dell xps_17_9710 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For dell's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.