Stack-Based Buffer Overflow in Dell PowerEdge and Precision Systems with Intel Optane
CVE-2021-21554

6.1MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
14 June 2021

Summary

A stack-based buffer overflow vulnerability exists in the BIOS of multiple Dell PowerEdge and Precision systems that use Intel Optane DC Persistent Memory. This vulnerability can be exploited by a local malicious user with elevated privileges, which may result in unauthorized access to sensitive information, denial of service, or arbitrary code execution within the UEFI or BIOS Preboot Environment. Organizations using the affected systems should implement necessary security measures to safeguard against potential exploitation.

Affected Version(s)

PowerEdge BIOS Intel 15G < 2.9.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.