DELL Dell BIOSConnect是美国戴尔(DELL)公司的一个基础平台,使 BIOS 可连接到 Dell 的 HTTP 后端,并通过 HTTP 方法加载映像。 Dell BIOSConnect feature and Dell HTTPS Boot feature 存在信任管理问题漏洞,该漏洞源于Dell UEFI BIOS https栈存在不正确的证书验证漏洞。未经身份验证的远程攻击者可利用该漏洞可以使用中间人攻击来利用这个漏洞,这种攻击可能导致拒绝服务和负载篡改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dell | UEFI BIOS https stack | Gen 11, Gen 10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-21572 | 7.2 HIGH | Dell BIOSConnect feature 缓冲区错误漏洞 |
| CVE-2021-21573 | 7.2 HIGH | Dell BIOSConnect feature 缓冲区错误漏洞 |
| CVE-2021-21574 | 7.2 HIGH | Dell BIOSConnect feature 缓冲区错误漏洞 |
No comments yet