Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.
📦
latitude_3420
Vendor: dell
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
9
Remote Access
Total CVEs
73
Total Indexed
Avg. EPSS
0.20%
Exploit Prob.
Security Vulnerability Index
Page 7 / 8
7.2
CVSS
CVE-2021-21573
RCE
Severity: HIGH
7.2
CVSS
CVE-2021-21572
RCE
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.
Severity: HIGH
5.9
CVSS
Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.
Severity: MEDIUM