CVE-2021-21522: High severity dell latitude 5285 firmware vulnerability
Dell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain access to sensitive information on an NVMe storage by resetting the BIOS password on the system via the Manageability Interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21522?
The severity of CVE-2021-21522 is classified as a medium risk due to its potential impact on sensitive information access.
Who is affected by CVE-2021-21522?
CVE-2021-21522 affects various models of Dell Latitude, Precision, and XPS laptops with specific firmware versions.
How do I fix CVE-2021-21522?
To fix CVE-2021-21522, update the BIOS firmware to the latest version provided by Dell.
What kind of information could be exposed by CVE-2021-21522?
CVE-2021-21522 may expose sensitive information stored on NVMe storage devices due to improper credentials management.
Is CVE-2021-21522 a remote exploit?
No, CVE-2021-21522 is a local exploit that requires authenticated access to the system.