CVE-2021-21557: Input Validation
Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management Mode.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-21557.
What is the severity of CVE-2021-21557?
The severity of CVE-2021-21557 is high.
What is affected by CVE-2021-21557?
Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS versions up to 2.11.2 are affected.
What can a local malicious user do with CVE-2021-21557?
A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of service, arbitrary code execution, or information disclosure in System Management (SysMa).
How can I fix CVE-2021-21557?
To fix CVE-2021-21557, Dell recommends updating to the latest BIOS version for the affected systems. Please refer to Dell's support website for specific instructions.