← Back

CVE-2021-21555

nvd nist
Published: Jun 14, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a heap-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.

Affected (9)

9 products
Poweredge R640 Firmware
Poweredge R740 Firmware
Poweredge R740xd Firmware
Poweredge R940 Firmware
Poweredge R840 Firmware
Poweredge R940xa Firmware
Poweredge T640 Firmware
Poweredge Mx740c Firmware
Poweredge Mx840c Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.11.2
Running on/withPlatform Versions
Dell
Poweredge R640
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.11.2
Running on/withPlatform Versions
Dell
Poweredge R740
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.11.2
Running on/withPlatform Versions
Dell
Poweredge R740xd
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.11.2
Running on/withPlatform Versions
Dell
Poweredge R940
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.11.2
Running on/withPlatform Versions
Dell
Poweredge R840
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.11.2
Running on/withPlatform Versions
Dell
Poweredge R940xa
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.11.2
Running on/withPlatform Versions
Dell
Poweredge T640
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.11.2
Running on/withPlatform Versions
Dell
Poweredge Mx740c
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.11.2
Running on/withPlatform Versions
Dell
Poweredge Mx840c
All versions

References (2)

Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.