cbcvebase.
CVE-2021-21522
published 2021-09-28

CVE-2021-21522: Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive…

PriorityP416medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.23%
13.4th percentile
Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
dellcpg_bios>= unspecified < 1.13.01.13.0
delllatitude_5285_2-in-1_firmware< 1.13.01.13.0
delllatitude_5289_2-in-1_firmware< 1.23.11.23.1
delllatitude_5290_2-in-1_firmware< 1.16.01.16.0
delllatitude_5310_2-in-1_firmware
delllatitude_7210_2-in-1_firmware< 1.7.01.7.0
delllatitude_7212_rugged_extreme_tablet_firmware< 1.33.01.33.0
delllatitude_7212_rugged_extreme_tablet_firmware
delllatitude_7280_firmware< 1.21.11.21.1
delllatitude_7280_firmware
delllatitude_7285_firmware< 1.11.01.11.0
delllatitude_7285_firmware
delllatitude_7290_firmware< 1.20.01.20.0
delllatitude_7290_firmware
delllatitude_7310_firmware< 1.7.01.7.0
delllatitude_7370_firmware< 1.24.31.24.3
delllatitude_7370_firmware
delllatitude_7380_firmware
delllatitude_7389_firmware< 1.23.11.23.1
delllatitude_7390_2-in-1_firmware< 1.19.01.19.0
delllatitude_7390_firmware
delllatitude_7410_firmware< 1.7.01.7.0
delllatitude_7420_firmware< 1.7.11.7.1
delllatitude_7480_firmware< 1.21.11.21.1
delllatitude_7490_firmware< 1.20.11.20.1

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.