Description
Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt mitigations in order to carry out a brute force attack.
Published: 2021-09-28
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-22905 Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt mitigations in order to carry out a brute force attack.
History

No history.

Subscriptions

Dell Latitude 5310 2-in-1 Latitude 5310 2-in-1 Firmware Latitude 5320 Latitude 5320 Firmware Latitude 5400 Latitude 5400 Firmware Latitude 5411 Latitude 5411 Firmware Latitude 5500 Latitude 5500 Firmware Latitude 5511 Latitude 5511 Firmware Latitude 5520 Latitude 5520 Firmware Latitude 7212 Rugged Extreme Tablet Latitude 7212 Rugged Extreme Tablet Firmware Latitude 7280 Latitude 7280 Firmware Latitude 7320 Latitude 7320 Firmware Latitude 7370 Latitude 7370 Firmware Latitude 7420 Latitude 7420 Firmware Latitude 7480 Latitude 7480 Firmware Latitude 9410 Latitude 9410 Firmware Latitude 9510 Latitude 9510 Firmware Latitude 9520 Latitude 9520 Firmware Optiplex 3080 Optiplex 3080 Firmware Optiplex 3280 Aio Optiplex 3280 Aio Firmware Optiplex 7480 Aio Optiplex 7480 Aio Firmware Precision 3551 Precision 3551 Ffirmware Precision 3640 Tower Precision 3640 Tower Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-17T03:37:29.343Z

Reserved: 2021-07-08T00:00:00.000Z

Link: CVE-2021-36285

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-28T20:15:07.673

Modified: 2024-11-21T06:13:25.617

Link: CVE-2021-36285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses