CVE Feed

    Dashboard / CVE / CVE-2021-21522

    CVE-2021-21522

    Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.

    Published:Sep 28, 2021
    Last Modified:Nov 21, 2024
    EPS:Sep 28, 2021
    EPSS Score:0.00043
    CVSS Score:8.2

    Affected Products

    Vendor
    Dell
    Product
    Latitude 5285 2-in-1
    Vendor
    Dell
    Product
    Latitude 5285 2-in-1 Firmware
    Vendor
    Dell
    Product
    Latitude 5289 2-in-1
    Vendor
    Dell
    Product
    Latitude 5289 2-in-1 Firmware
    Vendor
    Dell
    Product
    Latitude 5290 2-in-1
    Vendor
    Dell
    Product
    Latitude 5290 2-in-1 Firmware
    Vendor
    Dell
    Product
    Latitude 5310 2-in-1
    Vendor
    Dell
    Product
    Latitude 5310 2-in-1 Firmware
    Vendor
    Dell
    Product
    Latitude 7210 2-in-1
    Vendor
    Dell
    Product
    Latitude 7210 2-in-1 Firmware
    Vendor
    Dell
    Product
    Latitude 7212 Rugged Extreme Tablet
    Vendor
    Dell
    Product
    Latitude 7212 Rugged Extreme Tablet Firmware
    Vendor
    Dell
    Product
    Latitude 7280
    Vendor
    Dell
    Product
    Latitude 7280 Firmware
    Vendor
    Dell
    Product
    Latitude 7285
    Vendor
    Dell
    Product
    Latitude 7285 Firmware
    Vendor
    Dell
    Product
    Latitude 7290
    Vendor
    Dell
    Product
    Latitude 7290 Firmware
    Vendor
    Dell
    Product
    Latitude 7310
    Vendor
    Dell
    Product
    Latitude 7310 Firmware
    Vendor
    Dell
    Product
    Latitude 7370
    Vendor
    Dell
    Product
    Latitude 7370 Firmware
    Vendor
    Dell
    Product
    Latitude 7380
    Vendor
    Dell
    Product
    Latitude 7380 Firmware
    Vendor
    Dell
    Product
    Latitude 7389
    Vendor
    Dell
    Product
    Latitude 7389 Firmware
    Vendor
    Dell
    Product
    Latitude 7390
    Vendor
    Dell
    Product
    Latitude 7390 2-in-1
    Vendor
    Dell
    Product
    Latitude 7390 2-in-1 Firmware
    Vendor
    Dell
    Product
    Latitude 7390 Firmware
    Vendor
    Dell
    Product
    Latitude 7410
    Vendor
    Dell
    Product
    Latitude 7410 Firmware
    Vendor
    Dell
    Product
    Latitude 7420
    Vendor
    Dell
    Product
    Latitude 7420 Firmware
    Vendor
    Dell
    Product
    Latitude 7480
    Vendor
    Dell
    Product
    Latitude 7480 Firmware
    Vendor
    Dell
    Product
    Latitude 7490
    Vendor
    Dell
    Product
    Latitude 7490 Firmware
    Vendor
    Dell
    Product
    Latitude 9410
    Vendor
    Dell
    Product
    Latitude 9410 Firmware
    Vendor
    Dell
    Product
    Latitude 9510
    Vendor
    Dell
    Product
    Latitude 9510 Firmware
    Vendor
    Dell
    Product
    Precision 3640 Tower
    Vendor
    Dell
    Product
    Precision 3640 Tower Firmware
    Vendor
    Dell
    Product
    Precision 5510
    Vendor
    Dell
    Product
    Precision 5510 Firmware
    Vendor
    Dell
    Product
    Precision 5520
    Vendor
    Dell
    Product
    Precision 5520 Firmware
    Vendor
    Dell
    Product
    Precision 5530 2-in-1
    Vendor
    Dell
    Product
    Precision 5530 2-in-1 Firmware
    Vendor
    Dell
    Product
    Xps 13 9360
    Vendor
    Dell
    Product
    Xps 13 9360 Firmware
    Vendor
    Dell
    Product
    Xps 13 9370
    Vendor
    Dell
    Product
    Xps 13 9370 Firmware
    Vendor
    Dell
    Product
    Xps 15 9575 2-in-1
    Vendor
    Dell
    Product
    Xps 15 9575 2-in-1 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High