cbcvebase.
CVE-2021-21571
published 2021-06-24

CVE-2021-21571: Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A…

medium6.5CVSS 3.1
AVNACHPRNUINSUCNILAH
Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.

Affected

129 ranges· showing 25
VendorProductVersion rangeFixed in
dellalienware_m15_r6_firmware< 1.3.31.3.3
dellchengming_3990_firmware< 1.4.11.4.1
dellchengming_3991_firmware< 1.4.11.4.1
dellg15_5510_firmware< 1.4.01.4.0
dellg15_5511_firmware< 1.3.31.3.3
dellg3_3500_firmware< 1.9.01.9.0
dellg5_5500_firmware< 1.9.01.9.0
dellg7_7500_firmware< 1.9.01.9.0
dellg7_7700_firmware< 1.9.01.9.0
dellinspiron_14_5418_firmware< 2.1.0_a062.1.0_a06
dellinspiron_15_5518_firmware< 2.1.0_a062.1.0_a06
dellinspiron_15_7510_firmware< 1.0.41.0.4
dellinspiron_3501_firmware< 1.6.01.6.0
dellinspiron_3880_firmware< 1.4.11.4.1
dellinspiron_3881_firmware< 1.4.11.4.1
dellinspiron_3891_firmware< 1.0.111.0.11
dellinspiron_5300_firmware< 1.7.11.7.1
dellinspiron_5301_firmware< 1.8.11.8.1
dellinspiron_5310_firmware< 2.1.02.1.0
dellinspiron_5400_2-in-1_firmware< 1.7.01.7.0
dellinspiron_5400_aio_firmware< 1.4.01.4.0
dellinspiron_5401_aio_firmware< 1.4.01.4.0
dellinspiron_5401_firmware< 1.7.21.7.2
dellinspiron_5402_firmware< 1.5.11.5.1
dellinspiron_5406_2n1_firmware< 1.5.11.5.1