First published: Mon Jun 14 2021(Updated: )
Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a stack-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell PowerEdge R640 Firmware | <2.11.2 | |
Dell PowerEdge R640 Firmware | ||
Dell PowerEdge R740 Firmware | <2.11.2 | |
Dell PowerEdge R740 Firmware | ||
Dell PowerEdge R740xd Firmware | <2.11.2 | |
Dell PowerEdge R740xd2 | ||
Dell PowerEdge r940 firmware | <2.11.2 | |
Dell PowerEdge R940xa Firmware | ||
Dell PowerEdge R840 Firmware | <2.11.2 | |
Dell PowerEdge R840 Firmware | ||
Dell PowerEdge R940xa | <2.11.2 | |
Dell PowerEdge R940xa | ||
Dell PowerEdge T640 Firmware | <2.11.2 | |
Dell PowerEdge T640 | ||
Dell PowerEdge MX740c firmware | <2.11.2 | |
Dell PowerEdge MX740c | ||
Dell PowerEdge mx840c firmware | <2.11.2 | |
Dell PowerEdge MX840c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dell PowerEdge Server BIOS vulnerability is CVE-2021-21556.
The severity rating of CVE-2021-21556 is high.
The Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 server models are affected by this vulnerability.
Exploiting CVE-2021-21556 can lead to a denial of service (DoS) condition.
You can find more information about this vulnerability at the following reference link: [Dell Support KB Article](https://www.dell.com/support/kbdoc/000187958)