Stack-Based Buffer Overflow in Dell PowerEdge and Precision Systems with Intel Optane
CVE-2021-21554
6.1MEDIUM
Summary
A stack-based buffer overflow vulnerability exists in the BIOS of multiple Dell PowerEdge and Precision systems that use Intel Optane DC Persistent Memory. This vulnerability can be exploited by a local malicious user with elevated privileges, which may result in unauthorized access to sensitive information, denial of service, or arbitrary code execution within the UEFI or BIOS Preboot Environment. Organizations using the affected systems should implement necessary security measures to safeguard against potential exploitation.
Affected Version(s)
PowerEdge BIOS Intel 15G < 2.9.4
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved