Attacker Value
Unknown
0
CVE-2021-36283
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2021-36283
(Last updated November 28, 2024) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
6.7 Medium
Impact Score:
5.9
Exploitability Score:
0.8
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
CPG BIOS 1.3.1
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- chengming 3990 firmware,
- chengming 3991 firmware,
- g3 15 3500 firmware,
- g3 15 3590 firmware,
- g3 15 5500 firmware,
- inspiron 3493 firmware,
- inspiron 3501 firmware,
- inspiron 3593 firmware,
- inspiron 3793 firmware,
- inspiron 3880 firmware,
- inspiron 3881 firmware,
- inspiron 5400 2-in-1 firmware,
- inspiron 5490 firmware,
- inspiron 5493 firmware,
- inspiron 5498 firmware,
- inspiron 5590 firmware,
- inspiron 5593 firmware,
- inspiron 5598 firmware,
- inspiron 7391 2-in-1 firmware,
- inspiron 7500 2-in-1 silver firmware,
- inspiron 7500 firmware,
- inspiron 7501 firmware,
- inspiron 7590 firmware,
- inspiron 7591 firmware,
- latitude 3310 2-in-1 firmware,
- latitude 3310 firmware,
- latitude 5300 2-in-1 firmware,
- latitude 5300 firmware,
- latitude 5310 2 in 1 firmware 1.4.2,
- latitude 5310 firmware,
- latitude 5400 firmware,
- latitude 5401 firmware,
- latitude 5410 firmware,
- latitude 5411 firmware,
- latitude 5500 firmware,
- latitude 5511 firmware,
- latitude 7200 2 in 1 firmware,
- latitude 7210 2 in 1 firmware,
- latitude 7220ex rugged extreme tablet firmware,
- latitude 7300 firmware,
- latitude 7310 firmware,
- latitude 7400 2-in-1 firmware,
- latitude 7400 firmware,
- latitude 7410 firmware,
- latitude 9410 firmware,
- latitude 9510 firmware,
- optiplex 3080 firmware,
- optiplex 3280 aio firmware,
- optiplex 5080 firmware,
- optiplex 5480 aio firmware,
- optiplex 7080 firmware,
- optiplex 7480 aio firmware,
- optiplex 7780 aio firmware,
- precision 3440 firmware,
- precision 3540 firmware,
- precision 3541 firmware,
- precision 3550 firmware,
- precision 3551 firmware,
- precision 3640 tower firmware,
- precision 5540 firmware,
- precision 5550 firmware,
- precision 5750 firmware,
- precision 7540 firmware,
- precision 7550 firmware,
- precision 7740 firmware,
- precision 7750 firmware,
- vostro 3401 firmware,
- vostro 3491 firmware,
- vostro 3501 firmware,
- vostro 3591 firmware,
- vostro 3681 firmware,
- vostro 3881 firmware,
- vostro 3888 firmware,
- vostro 5490 firmware,
- vostro 5590 firmware,
- vostro 7500 firmware,
- vostro 7590 firmware,
- wyse 5470 firmware,
- xps 13 9300 firmware,
- xps 13 9380 firmware,
- xps 17 9700 firmware,
- xps 7380 firmware,
- xps 7390 2-in-1 firmware,
- xps 7590 firmware,
- xps 9500 firmware
References
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: