First published: Mon Jun 14 2021(Updated: )
Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management Mode.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Poweredge R640 Firmware | <2.11.2 | |
Dell PowerEdge R640 | ||
Dell Poweredge R740 Firmware | <2.11.2 | |
Dell Poweredge R740 | ||
Dell Poweredge R740xd Firmware | <2.11.2 | |
Dell Poweredge R740xd | ||
Dell Poweredge R940 Firmware | <2.11.2 | |
Dell Poweredge R940 | ||
Dell Poweredge R540 Firmware | <2.11.2 | |
Dell Poweredge R540 | ||
Dell Poweredge R440 Firmware | <2.11.2 | |
Dell Poweredge R440 | ||
Dell Poweredge T440 Firmware | <2.11.2 | |
Dell Poweredge T440 | ||
Dell Poweredge Xr2 Firmware | <2.11.2 | |
Dell Poweredge Xr2 | ||
Dell Poweredge R740xd2 Firmware | <2.11.2 | |
Dell Poweredge R740xd2 | ||
Dell Poweredge R840 Firmware | <2.11.2 | |
Dell Poweredge R840 | ||
Dell Poweredge R940xa Firmware | <2.11.2 | |
Dell Poweredge R940xa | ||
Dell Poweredge T640 Firmware | <2.11.2 | |
Dell Poweredge T640 | ||
Dell Poweredge C6420 Firmware | <2.11.2 | |
Dell Poweredge C6420 | ||
Dell Poweredge Fc640 Firmware | <2.11.2 | |
Dell Poweredge Fc640 | ||
Dell Poweredge M640 Firmware | <2.11.2 | |
Dell Poweredge M640 | ||
Dell Poweredge M640p Firmware | <2.11.2 | |
Dell Poweredge M640p | ||
Dell Poweredge Mx740c Firmware | <2.11.2 | |
Dell Poweredge Mx740c | ||
Dell Poweredge Mx840c Firmware | <2.11.2 | |
Dell Poweredge Mx840c | ||
Dell Poweredge C4140 Firmware | <2.11.2 | |
Dell Poweredge C4140 | ||
Dell Poweredge T140 Firmware | <2.5.1 | |
Dell Poweredge T140 | ||
Dell Poweredge T340 Firmware | <2.5.1 | |
Dell Poweredge T340 | ||
Dell Poweredge R240 Firmware | <2.5.1 | |
Dell Poweredge R240 | ||
Dell Poweredge R340 Firmware | <2.5.1 | |
Dell Poweredge R340 | ||
Dell Poweredge R6415 Firmware | <1.16.1 | |
Dell Poweredge R6415 | ||
Dell Poweredge R7415 Firmware | <1.16.1 | |
Dell Poweredge R7415 | ||
Dell Poweredge R7425 Firmware | <1.16.1 | |
Dell Poweredge R7425 | ||
Dell Poweredge R6515 Firmware | <2.2.4 | |
Dell Poweredge R6515 | ||
Dell Poweredge R7515 Firmware | <2.2.4 | |
Dell Poweredge R7515 | ||
Dell Poweredge R6525 Firmware | <2.2.5 | |
Dell Poweredge R6525 | ||
Dell Poweredge R7525 Firmware | <2.2.5 | |
Dell Poweredge R7525 | ||
Dell Poweredge C6525 Firmware | <2.2.4 | |
Dell Poweredge C6525 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-21557.
The severity of CVE-2021-21557 is high.
Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS versions up to 2.11.2 are affected.
A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management (SysMa).
To fix CVE-2021-21557, Dell recommends updating to the latest BIOS version for the affected systems. Please refer to Dell's support website for specific instructions.