CVE-2021-21555
Summary
| CVE | CVE-2021-21555 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-14 19:15:00 UTC |
| Updated | 2021-06-23 18:21:00 UTC |
| Description | Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a heap-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dell | Poweredge Mx740c | - | All | All | All |
| Operating System | Dell | Poweredge Mx740c Firmware | All | All | All | All |
| Hardware | Dell | Poweredge Mx840c | - | All | All | All |
| Operating System | Dell | Poweredge Mx840c Firmware | All | All | All | All |
| Hardware | Dell | Poweredge R640 | - | All | All | All |
| Operating System | Dell | Poweredge R640 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge R740 | - | All | All | All |
| Hardware | Dell | Poweredge R740xd | - | All | All | All |
| Operating System | Dell | Poweredge R740xd Firmware | All | All | All | All |
| Operating System | Dell | Poweredge R740 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge R840 | - | All | All | All |
| Operating System | Dell | Poweredge R840 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge R940 | - | All | All | All |
| Hardware | Dell | Poweredge R940xa | - | All | All | All |
| Operating System | Dell | Poweredge R940xa Firmware | All | All | All | All |
| Operating System | Dell | Poweredge R940 Firmware | All | All | All | All |
| Hardware | Dell | Poweredge T640 | - | All | All | All |
| Operating System | Dell | Poweredge T640 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access Denied | CONFIRM | www.dell.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.