CVE-2021-36283

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
28/09/2021
Last modified:
04/10/2021

Description

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:chengming_3990_firmware:*:*:*:*:*:*:*:* 1.3.1 (excluding)
cpe:2.3:h:dell:chengming_3990:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:chengming_3991_firmware:*:*:*:*:*:*:*:* 1.3.1 (excluding)
cpe:2.3:h:dell:chengming_3991:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g3_15_3500_firmware:*:*:*:*:*:*:*:* 1.7.1 (excluding)
cpe:2.3:h:dell:g3_15_3500:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g3_15_3590_firmware:*:*:*:*:*:*:*:* 1.12.0 (excluding)
cpe:2.3:h:dell:g3_15_3590:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:g3_15_5500_firmware:*:*:*:*:*:*:*:* 1.7.1 (excluding)
cpe:2.3:h:dell:g3_15_5500:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_3493_firmware:*:*:*:*:*:*:*:* 1.12.0 (excluding)
cpe:2.3:h:dell:inspiron_3493:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_3501_firmware:*:*:*:*:*:*:*:* 1.1.0 (excluding)
cpe:2.3:h:dell:inspiron_3501:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:inspiron_3593_firmware:*:*:*:*:*:*:*:* 1.12.0 (excluding)


References to Advisories, Solutions, and Tools