PT-2021-14602 · Dell+1 · Dell Precision 7920 Rack Workstation Bios+7

Alexander Matrosov

+1

·

Published

2021-06-14

·

Updated

2022-10-25

·

CVE-2021-21554

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and Dell Precision 7920 Rack Workstation BIOS (affected versions not specified)
Description The issue is a stack-based buffer overflow vulnerability in systems with Intel Optane DC Persistent Memory installed. A local malicious user with high privileges may potentially exploit this, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2021-21554

Affected Products

Dell Mx740C
Dell Mx840C
Dell Poweredge R640
Dell Poweredge R740
Dell Poweredge R840
Dell Poweredge R940
Dell Precision 7920 Rack Workstation Bios
Intel Optane Dc Persistent Memory