CVE-2021-36284

CWE-3073 documents3 sources
Severity
4.4MEDIUM
EPSS
0.0%
top 85.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 28
Latest updateMay 24

Description

Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive admin password attempt mitigations in order to carry out a brute force attack.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:LExploitability: 1.5 | Impact: 3.7

Affected Packages22 packages

CVEListV5dell/cpg_biosunspecified1.7.0

🔴Vulnerability Details

2
GHSA
GHSA-pw9c-57vv-q8c2: Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability2022-05-24
CVEList
CVE-2021-36284: Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability2021-09-28
CVE-2021-36284 (MEDIUM CVSS 4.4) | Dell BIOS contains an Improper Rest | cvebase.io