CVE-2021-36284

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/09/2021
Last modified:
04/10/2021

Description

Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive admin password attempt mitigations in order to carry out a brute force attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:latitude_5310_2-in-1_firmware:*:*:*:*:*:*:*:* 1.7.0 (excluding)
cpe:2.3:h:dell:latitude_5310_2-in-1:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:latitude_5320_firmware:*:*:*:*:*:*:*:* 1.7.0 (excluding)
cpe:2.3:h:dell:latitude_5320:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:latitude_5400_firmware:*:*:*:*:*:*:*:* 1.7.1 (excluding)
cpe:2.3:h:dell:latitude_5400:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:latitude_5411_firmware:*:*:*:*:*:*:*:* 1.6.0 (excluding)
cpe:2.3:h:dell:latitude_5411:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:latitude_5500_firmware:*:*:*:*:*:*:*:* 1.8.0 (excluding)
cpe:2.3:h:dell:latitude_5500:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:latitude_5520_firmware:*:*:*:*:*:*:*:* 1.6.0 (excluding)
cpe:2.3:h:dell:latitude_5520:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:latitude_5511_firmware:*:*:*:*:*:*:*:* 1.7.1 (excluding)
cpe:2.3:h:dell:latitude_5511:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:latitude_7212_rugged_extreme_tablet_firmware:*:*:*:*:*:*:*:* 1.7.0 (excluding)


References to Advisories, Solutions, and Tools