CVE-2021-21571
published 2021-06-24CVE-2021-21571: Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A…
medium6.5CVSS 3.1
AVNACHPRNUINSUCNILAH
Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.
Affected
129 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | alienware_m15_r6_firmware | < 1.3.3 | 1.3.3 |
| dell | chengming_3990_firmware | < 1.4.1 | 1.4.1 |
| dell | chengming_3991_firmware | < 1.4.1 | 1.4.1 |
| dell | g15_5510_firmware | < 1.4.0 | 1.4.0 |
| dell | g15_5511_firmware | < 1.3.3 | 1.3.3 |
| dell | g3_3500_firmware | < 1.9.0 | 1.9.0 |
| dell | g5_5500_firmware | < 1.9.0 | 1.9.0 |
| dell | g7_7500_firmware | < 1.9.0 | 1.9.0 |
| dell | g7_7700_firmware | < 1.9.0 | 1.9.0 |
| dell | inspiron_14_5418_firmware | < 2.1.0_a06 | 2.1.0_a06 |
| dell | inspiron_15_5518_firmware | < 2.1.0_a06 | 2.1.0_a06 |
| dell | inspiron_15_7510_firmware | < 1.0.4 | 1.0.4 |
| dell | inspiron_3501_firmware | < 1.6.0 | 1.6.0 |
| dell | inspiron_3880_firmware | < 1.4.1 | 1.4.1 |
| dell | inspiron_3881_firmware | < 1.4.1 | 1.4.1 |
| dell | inspiron_3891_firmware | < 1.0.11 | 1.0.11 |
| dell | inspiron_5300_firmware | < 1.7.1 | 1.7.1 |
| dell | inspiron_5301_firmware | < 1.8.1 | 1.8.1 |
| dell | inspiron_5310_firmware | < 2.1.0 | 2.1.0 |
| dell | inspiron_5400_2-in-1_firmware | < 1.7.0 | 1.7.0 |
| dell | inspiron_5400_aio_firmware | < 1.4.0 | 1.4.0 |
| dell | inspiron_5401_aio_firmware | < 1.4.0 | 1.4.0 |
| dell | inspiron_5401_firmware | < 1.7.2 | 1.7.2 |
| dell | inspiron_5402_firmware | < 1.5.1 | 1.5.1 |
| dell | inspiron_5406_2n1_firmware | < 1.5.1 | 1.5.1 |