CVE Feed

    Dashboard / CVE / CVE-2021-21557

    CVE-2021-21557

    Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management Mode.

    Published:Jun 14, 2021
    Last Modified:Nov 21, 2024
    EPS:Jun 14, 2021
    EPSS Score:0.00042
    CVSS Score:8.1

    Affected Products

    Vendor
    Dell
    Product
    Poweredge C4140
    Vendor
    Dell
    Product
    Poweredge C4140 Firmware
    Vendor
    Dell
    Product
    Poweredge C6420
    Vendor
    Dell
    Product
    Poweredge C6420 Firmware
    Vendor
    Dell
    Product
    Poweredge C6525
    Vendor
    Dell
    Product
    Poweredge C6525 Firmware
    Vendor
    Dell
    Product
    Poweredge Fc640
    Vendor
    Dell
    Product
    Poweredge Fc640 Firmware
    Vendor
    Dell
    Product
    Poweredge M640
    Vendor
    Dell
    Product
    Poweredge M640 Firmware
    Vendor
    Dell
    Product
    Poweredge M640p
    Vendor
    Dell
    Product
    Poweredge M640p Firmware
    Vendor
    Dell
    Product
    Poweredge Mx740c
    Vendor
    Dell
    Product
    Poweredge Mx740c Firmware
    Vendor
    Dell
    Product
    Poweredge Mx840c
    Vendor
    Dell
    Product
    Poweredge Mx840c Firmware
    Vendor
    Dell
    Product
    Poweredge R240
    Vendor
    Dell
    Product
    Poweredge R240 Firmware
    Vendor
    Dell
    Product
    Poweredge R340
    Vendor
    Dell
    Product
    Poweredge R340 Firmware
    Vendor
    Dell
    Product
    Poweredge R440
    Vendor
    Dell
    Product
    Poweredge R440 Firmware
    Vendor
    Dell
    Product
    Poweredge R540
    Vendor
    Dell
    Product
    Poweredge R540 Firmware
    Vendor
    Dell
    Product
    Poweredge R640
    Vendor
    Dell
    Product
    Poweredge R640 Firmware
    Vendor
    Dell
    Product
    Poweredge R6415
    Vendor
    Dell
    Product
    Poweredge R6415 Firmware
    Vendor
    Dell
    Product
    Poweredge R6515
    Vendor
    Dell
    Product
    Poweredge R6515 Firmware
    Vendor
    Dell
    Product
    Poweredge R6525
    Vendor
    Dell
    Product
    Poweredge R6525 Firmware
    Vendor
    Dell
    Product
    Poweredge R740
    Vendor
    Dell
    Product
    Poweredge R740 Firmware
    Vendor
    Dell
    Product
    Poweredge R740xd
    Vendor
    Dell
    Product
    Poweredge R740xd2
    Vendor
    Dell
    Product
    Poweredge R740xd2 Firmware
    Vendor
    Dell
    Product
    Poweredge R740xd Firmware
    Vendor
    Dell
    Product
    Poweredge R7415
    Vendor
    Dell
    Product
    Poweredge R7415 Firmware
    Vendor
    Dell
    Product
    Poweredge R7425
    Vendor
    Dell
    Product
    Poweredge R7425 Firmware
    Vendor
    Dell
    Product
    Poweredge R7515
    Vendor
    Dell
    Product
    Poweredge R7515 Firmware
    Vendor
    Dell
    Product
    Poweredge R7525
    Vendor
    Dell
    Product
    Poweredge R7525 Firmware
    Vendor
    Dell
    Product
    Poweredge R840
    Vendor
    Dell
    Product
    Poweredge R840 Firmware
    Vendor
    Dell
    Product
    Poweredge R940
    Vendor
    Dell
    Product
    Poweredge R940 Firmware
    Vendor
    Dell
    Product
    Poweredge R940xa
    Vendor
    Dell
    Product
    Poweredge R940xa Firmware
    Vendor
    Dell
    Product
    Poweredge T140
    Vendor
    Dell
    Product
    Poweredge T140 Firmware
    Vendor
    Dell
    Product
    Poweredge T340
    Vendor
    Dell
    Product
    Poweredge T340 Firmware
    Vendor
    Dell
    Product
    Poweredge T440
    Vendor
    Dell
    Product
    Poweredge T440 Firmware
    Vendor
    Dell
    Product
    Poweredge T640
    Vendor
    Dell
    Product
    Poweredge T640 Firmware
    Vendor
    Dell
    Product
    Poweredge Xr2
    Vendor
    Dell
    Product
    Poweredge Xr2 Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High