Dell Releases Patch for BIOS Flaws That Put Over 30 Million Devices at Risk of Remote Attacks

The security flaws affect as many as 129 models of Dell laptops, desktops, and tablets.

Advertisement
By Jagmeet Singh | Updated: 25 June 2021 12:52 IST
Highlights
  • Dell machines are affected by the flaws that existed in BIOSConnect
  • Eclypsium researchers reported about the vulnerabilities
  • Dell Latitude and Alienware laptops are amongst the impacted machines

Dell has released a BIOS update to patch the reported vulnerabilities

Photo Credit: Reuters

Dell laptops, desktops, and tablets have four "severe" vulnerabilities that could let hackers take over the devices, affecting over 30 million computers. The company confirmed this and has released a patch for the vulnerability in its BIOSConnect feature. This is designed to enable remote recovery and firmware updates, but also left a door open to hackers. Dell has issued an advisory in response to the vulnerabilities and has started releasing patches for its BIOS available on all of the affected devices.

Security researchers at enterprise device security company Eclypsium discovered the vulnerabilities and researchers said that the issues affect as many as 129 types of Dell laptops, desktops, and tablets. This includes models that are meant specifically for enterprises and are protected by the Secure Boot security standard.

Dell has acknowledged the existence of all four vulnerabilities reported by the Eclypsium researchers. It has also started rolling out patches for BIOS that users can download upon their arrival. Meanwhile, the company has also advised users to disable BIOSConnect. A couple of workarounds for that have been provided on the company's support page.

Advertisement

"These vulnerabilities enable an attacker to remotely execute code in the pre-boot environment. Such code may alter the initial state of an operating system, violating common assumptions on the hardware/ firmware layers and breaking OS-level security controls," the researchers said. The vulnerabilities were discovered on March 2, and Dell was notified about them on March 3, according to Eclypsium.

Advertisement

BIOSConnect is a feature of Dell's SupportAssist remote support system, and comes pre-installed on most Windows-based Dell computers. For companies, this lets them update the firmware and perform remote OS recovery for their employee's laptops and computers. In theory, this should make the machines more secure as the enterprise is able to ensure that everyone's computers are up to date.

Researchers however found that BIOSConnect itself opened the computers up to serious security threats. Of the four vulnerabilities discovered in the preloaded feature, one that is noted as CVE-2021-21571 allows insecure connections for firmware updates.

Advertisement

"When attempting to connect to the backend Dell HTTP server, the TLS connection from BIOSConnect will accept any valid wildcard certificate. This allows an attacker with a privileged network position to impersonate Dell and deliver attacker-controlled content back to the victim device," the researchers explained.

The remaining three issues are classified as overflow vulnerabilities (CVE-2021-21572, CVE-2021-21573, CVE-2021-21574) that could help attackers execute arbitrary code. Two of them are found to be affecting the OS recovery process, while the other one impacts the process of updating the firmware. The researchers said that all three of these vulnerabilities are independent and any of them could be used to execute malicious code in BIOS.

Advertisement

Who all are affected by Dell's BIOSConnect security vulnerability?

The list of affected devices that have started getting BIOS patches includes some recently launched laptops such as the Alienware m15 R6, Dell G5 15 5500, Dell G7 (7500), Dell Inspiron 13 (5310), and the Dell Latitude 7320. There are also recent desktop models such as the OptiPlex 7090 Tower, and the OptiPlex 7780 All-in-One.

This isn't the first time Dell computers are found to be affected by security vulnerabilities. In May, Dell released a security patch for its firmware update driver module to fix as many as five high-severity flaws that had been in use since 2009. The SupportAssist tool also received a fix in 2019 for a critical flaw that had left millions of systems at risk of a privilege-escalation attack.


What were the best games at E3 2021? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement
Popular Mobile Brands
  1. These OnePlus, Samsung Phones Will Be on Sale During Amazon's Next Sale
  2. Amazon Great Republic Day Sale 2026: iQOO Smartphone Deals Revealed
  3. Vivo Y500i With a 7,200mAh Battery, 50-Megapixel Camera Launched
  4. Vivo X200T Confirmed to Launch in India Soon: Expected Specs
  5. Redmi Turbo 5 Pro Max Could Launch With This MediaTek Dimensity Chipset
  6. Grok Banned in Indonesia and Malaysia Following Deepfake Image Concerns
  7. Instagram Denies Reports of Data Breach, Says 'Accounts Are Secure'
  8. Disney+ to Launch Vertical Video Feed to Rival TikTok, YouTube Shorts
  9. Google Adds AI-Powered 'Business Agent' Feature to Search for Shoppers
  10. Apple AirPods Pro 3 Review: The New Gold Standard
  1. Mahasenha Volume 1 OTT Release Date: When and Where to Watch This Mystical Thriller Online?
  2. Kirkkan OTT Release Date Confirmed: When and Where to Watch it Online?
  3. OnePlus 15T Colourways, RAM, Storage Variants Leaked Online; Tipped to Launch With Snapdragon 8 Elite Gen 5 SoC
  4. Vivo X200T India Launch Teased; Flipkart Availability Confirmed: Expected Specifications
  5. Bitcoin Trades Flat as Crypto Markets Enter Consolidation Phase
  6. Forza Horizon 6 and Fable Gameplay to Debut at Xbox Developer Direct on January 22
  7. Instagram Denies Reports of Hacking and Data Breach, Says ‘Accounts Are Secure’
  8. Shell OTT Release Date: When and Where to Watch Elizabeth Moss and Kate Hudson’s Psychological Drama Online?
  9. Nikita Roy Now Available for Streaming on JioHotstar: Know Everything About Sonakshi Sinha’s Mystery Horror Film
  10. iPhone 16, Vivo T4x 5G to Go on Sale at Discounted Prices During Flipkart Republic Day Sale 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.