CVE-2021-21557

Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management Mode.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
dellCNA
8.1 HIGH
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
dellpoweredge_r640_firmware
𝑥
< 2.11.2
dellpoweredge_r740_firmware
𝑥
< 2.11.2
dellpoweredge_r740xd_firmware
𝑥
< 2.11.2
dellpoweredge_r940_firmware
𝑥
< 2.11.2
dellpoweredge_r540_firmware
𝑥
< 2.11.2
dellpoweredge_r440_firmware
𝑥
< 2.11.2
dellpoweredge_t440_firmware
𝑥
< 2.11.2
dellpoweredge_xr2_firmware
𝑥
< 2.11.2
dellpoweredge_r740xd2_firmware
𝑥
< 2.11.2
dellpoweredge_r840_firmware
𝑥
< 2.11.2
dellpoweredge_r940xa_firmware
𝑥
< 2.11.2
dellpoweredge_t640_firmware
𝑥
< 2.11.2
dellpoweredge_c6420_firmware
𝑥
< 2.11.2
dellpoweredge_fc640_firmware
𝑥
< 2.11.2
dellpoweredge_m640_firmware
𝑥
< 2.11.2
dellpoweredge_m640p_firmware
𝑥
< 2.11.2
dellpoweredge_mx740c_firmware
𝑥
< 2.11.2
dellpoweredge_mx840c_firmware
𝑥
< 2.11.2
dellpoweredge_c4140_firmware
𝑥
< 2.11.2
dellpoweredge_t140_firmware
𝑥
< 2.5.1
dellpoweredge_t340_firmware
𝑥
< 2.5.1
dellpoweredge_r240_firmware
𝑥
< 2.5.1
dellpoweredge_r340_firmware
𝑥
< 2.5.1
dellpoweredge_r6415_firmware
𝑥
< 1.16.1
dellpoweredge_r7415_firmware
𝑥
< 1.16.1
dellpoweredge_r7425_firmware
𝑥
< 1.16.1
dellpoweredge_r6515_firmware
𝑥
< 2.2.4
dellpoweredge_r7515_firmware
𝑥
< 2.2.4
dellpoweredge_r6525_firmware
𝑥
< 2.2.5
dellpoweredge_r7525_firmware
𝑥
< 2.2.5
dellpoweredge_c6525_firmware
𝑥
< 2.2.4
𝑥
= Vulnerable software versions