ID

VAR-202108-1844


CVE

CVE-2021-36277


TITLE

Dell Command Update  and  Alienware Update  Digital Signature Verification Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2021-009798

DESCRIPTION

Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability. A local authenticated malicious user may exploit this vulnerability by executing arbitrary code on the system

Trust: 1.8

sources: NVD: CVE-2021-36277 // JVNDB: JVNDB-2021-009798 // VULHUB: VHN-396983 // VULMON: CVE-2021-36277

AFFECTED PRODUCTS

vendor:dellmodel:command \| updatescope:ltversion:4.3.0

Trust: 1.0

vendor:dellmodel:update\/alienware updatescope:ltversion:4.3.0

Trust: 1.0

vendor:dellmodel:alienware command center applicationscope:ltversion:5.4.35.0

Trust: 1.0

vendor:デルmodel:dell update/alienware updatescope:eqversion:4.3

Trust: 0.8

vendor:デルmodel:dell command updatescope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-009798 // NVD: CVE-2021-36277

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-36277
value: HIGH

Trust: 1.0

security_alert@emc.com: CVE-2021-36277
value: HIGH

Trust: 1.0

NVD: CVE-2021-36277
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202108-824
value: HIGH

Trust: 0.6

VULHUB: VHN-396983
value: HIGH

Trust: 0.1

VULMON: CVE-2021-36277
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2021-36277
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-396983
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-36277
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 2.0

OTHER: JVNDB-2021-009798
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-396983 // VULMON: CVE-2021-36277 // JVNDB: JVNDB-2021-009798 // CNNVD: CNNVD-202108-824 // NVD: CVE-2021-36277 // NVD: CVE-2021-36277

PROBLEMTYPE DATA

problemtype:CWE-347

Trust: 1.1

problemtype:Improper verification of digital signatures (CWE-347) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-396983 // JVNDB: JVNDB-2021-009798 // NVD: CVE-2021-36277

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202108-824

TYPE

data forgery

Trust: 0.6

sources: CNNVD: CNNVD-202108-824

PATCH

title:DSA-2021-154url:https://www.dell.com/support/kbdoc/ja-jp/000190110/dsa-2021-154-dell-command-update-dell-update-alienware-update-security-update-for-a-dll-injection-vulnerability

Trust: 0.8

title:DELL Dell Command Update Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=159133

Trust: 0.6

title: - url:https://github.com/Live-Hack-CVE/CVE-2021-36277

Trust: 0.1

sources: VULMON: CVE-2021-36277 // JVNDB: JVNDB-2021-009798 // CNNVD: CNNVD-202108-824

EXTERNAL IDS

db:NVDid:CVE-2021-36277

Trust: 3.4

db:JVNDBid:JVNDB-2021-009798

Trust: 0.8

db:CNNVDid:CNNVD-202108-824

Trust: 0.7

db:VULHUBid:VHN-396983

Trust: 0.1

db:VULMONid:CVE-2021-36277

Trust: 0.1

sources: VULHUB: VHN-396983 // VULMON: CVE-2021-36277 // JVNDB: JVNDB-2021-009798 // CNNVD: CNNVD-202108-824 // NVD: CVE-2021-36277

REFERENCES

url:https://www.dell.com/support/kbdoc/000190110

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2021-36277

Trust: 0.8

url:https://www.dell.com/support/kbdoc/en-us/000190110

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/347.html

Trust: 0.1

url:https://github.com/live-hack-cve/cve-2021-36277

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-396983 // VULMON: CVE-2021-36277 // JVNDB: JVNDB-2021-009798 // CNNVD: CNNVD-202108-824 // NVD: CVE-2021-36277

SOURCES

db:VULHUBid:VHN-396983
db:VULMONid:CVE-2021-36277
db:JVNDBid:JVNDB-2021-009798
db:CNNVDid:CNNVD-202108-824
db:NVDid:CVE-2021-36277

LAST UPDATE DATE

2024-08-14T14:31:38.985000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-396983date:2023-02-10T00:00:00
db:VULMONid:CVE-2021-36277date:2022-09-02T00:00:00
db:JVNDBid:JVNDB-2021-009798date:2022-05-24T09:17:00
db:CNNVDid:CNNVD-202108-824date:2022-09-05T00:00:00
db:NVDid:CVE-2021-36277date:2023-02-10T17:28:33.600

SOURCES RELEASE DATE

db:VULHUBid:VHN-396983date:2021-08-09T00:00:00
db:VULMONid:CVE-2021-36277date:2021-08-09T00:00:00
db:JVNDBid:JVNDB-2021-009798date:2022-05-24T00:00:00
db:CNNVDid:CNNVD-202108-824date:2021-08-09T00:00:00
db:NVDid:CVE-2021-36277date:2021-08-09T21:15:08.417