CVE-2021-21557

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
14/06/2021
Last modified:
25/10/2022

Description

Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management Mode.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:poweredge_r640_firmware:*:*:*:*:*:*:*:* 2.11.2 (excluding)
cpe:2.3:h:dell:poweredge_r640:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_r740_firmware:*:*:*:*:*:*:*:* 2.11.2 (excluding)
cpe:2.3:h:dell:poweredge_r740:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_r740xd_firmware:*:*:*:*:*:*:*:* 2.11.2 (excluding)
cpe:2.3:h:dell:poweredge_r740xd:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_r940_firmware:*:*:*:*:*:*:*:* 2.11.2 (excluding)
cpe:2.3:h:dell:poweredge_r940:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_r540_firmware:*:*:*:*:*:*:*:* 2.11.2 (excluding)
cpe:2.3:h:dell:poweredge_r540:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_r440_firmware:*:*:*:*:*:*:*:* 2.11.2 (excluding)
cpe:2.3:h:dell:poweredge_r440:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_t440_firmware:*:*:*:*:*:*:*:* 2.11.2 (excluding)
cpe:2.3:h:dell:poweredge_t440:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:poweredge_xr2_firmware:*:*:*:*:*:*:*:* 2.11.2 (excluding)


References to Advisories, Solutions, and Tools