{"id":7480,"date":"2021-06-25T09:30:32","date_gmt":"2021-06-25T13:30:32","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=7480"},"modified":"2021-07-23T14:04:26","modified_gmt":"2021-07-23T18:04:26","slug":"dell-supportassist-bugs-affects-30-million-pcs","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/dell-supportassist-bugs-affects-30-million-pcs\/","title":{"rendered":"Dell SupportAssist Bugs Affects 30 Million PCs"},"content":{"rendered":"\n<p>According to reports, security researchers recently discovered four major vulnerabilities in BIOSConnect, a feature of Dell SupportAssist that provides firmware updates and OS recovery features.<\/p>\n\n\n\n<p>Eclypsium researchers, the researchers behind the discovery explained that an identified problem tracked as CVE-2021-21571 led to an insecure TLS connection from BIOS to Dell along with three overflow vulnerabilities tracked as CVE-2021-21572, CVE-2021-21573 and CVE-2021-21574.<\/p>\n\n\n\n<p>The vulnerabilities also come with a CVSS base value of 8.3\/10 that allows privileged remote attackers to imitate Dell.com while taking control of the target device boot process to break OS-level security controls.<\/p>\n\n\n\n<p>In a report shared with Bleeping Computer, the researchers from Eclypsium said: &#8220;Such an attack would enable adversaries to control the device&#8217;s boot process and subvert the operating system and higher-layer security controls. The issue affects 129 Dell models of consumer and business laptops, desktops, and tablets, including devices protected by Secure Boot and Dell Secured-core PCs.&#8221;<\/p>\n\n\n\n<p>The researchers also gave a rough estimate of the devices exposed during the attack at about 30 million.<\/p>\n\n\n<p>For more information, read the <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/dell-supportassist-bugs-put-over-30-million-pcs-at-risk\/\" target=\"_blank\" rel=\"noopener\">original story<\/a> in Bleeping Computer.<\/p>","protected":false},"excerpt":{"rendered":"<p>According to reports, security researchers recently discovered four major vulnerabilities in BIOSConnect, a feature of Dell SupportAssist that provides firmware updates and OS recovery features. Eclypsium researchers, the researchers behind the discovery explained that an identified problem tracked as CVE-2021-21571 led to an insecure TLS connection from BIOS to Dell along with three overflow vulnerabilities [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16],"tags":[217],"class_list":["post-7480","post","type-post","status-publish","format-standard","hentry","category-security","tag-dell"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/7480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=7480"}],"version-history":[{"count":3,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/7480\/revisions"}],"predecessor-version":[{"id":7510,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/7480\/revisions\/7510"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=7480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=7480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=7480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}