30 Million Dell Devices Have Been Shipped With ‘Severe Security Flaws' In Its Software

While most computers are either shipped with operating systems, like Windows or Linux, it's still up to their manufacturers if they want to equip their devices with additional proprietary software.

Dell for example, is an American multinational computer technology company that develops, sells, repairs, and supports computers and related products and services. It is the world's 3rd largest personal computer vendor by unit sales as of January 2021, by conquering 16.4% of the market.

Dell has what it calls the BIOSConnect, which allows it to update and operate its recovery software. This BIOSConnect is found to have security issues.

According to researchers at security fim Eclypsium, the issue at BIOSCONNECT exposes tens of millions of Dell devices at risk.

BIOSConnect is part of Dell’s standard SupportAssist software and updates the firmware on a computer’s system board. And the flaws that happen to be found in it, could allow attackers to remotely execute malicious code.

The researchers wrote that the vulnerability was so severe it could “enable adversaries to control the device’s boot process and subvert the operating system and higher-layer security controls,” which would in turn give them control “over the most privileged code on the device.”

BIOSConnect Attack Scenario.
Credit: Dell)

In total, the researchers found four separate vulnerabilities.

One of which involves insecure connections between a BIOS being updated and Dell’s servers that allow an attacker to redirect the machine to a maliciously modified update package. The remaining three are classified as overflow vulnerabilities.

Dell preinstalled the software on 129 different models of Dell laptops, tablets, and desktops, and at least 30 million individual devices.

And because of that, according to Eclypsium's estimates, around 30 million individual Dell devices are potentially vulnerable.

"The issue has been found on Secured-core PCs even if Secure Boot is enabled," the researchers said.

Eclypsium first notified Dell of the flaws in March 2021. Dell released fixes to all four bugs.

Two bugs (CVE-2021-21573 and CVE-2021-21574) were fixed through a server-side update, and the remaining two (CVE-2021-21571 and CVE-2021-21572) require users to manually update the BIOS/UEFI on each device.

[block:block=87]

In a blog post, Eclypsium wrote:

"Eclypsium researchers have identified multiple vulnerabilities affecting the BIOSConnect feature within Dell Client BIOS. This chain of vulnerabilities has a cumulative CVSS score of 8.3 (High) because it allows a privileged network adversary to impersonate Dell.com and gain arbitrary code execution at the BIOS/UEFI level of the affected device. Such an attack would enable adversaries to control the device’s boot process and subvert the operating system and higher-layer security controls. The issue affects 129 Dell models of consumer and business laptops, desktops, and tablets, including devices protected by Secure Boot and Dell Secured-core PCs."

"These vulnerabilities enable an attacker to remotely execute code in the pre-boot environment. Such code may alter the initial state of an operating system, violating common assumptions on the hardware/firmware layers and breaking OS-level security controls. As attackers increasingly shift their focus to vendor supply chains and system firmware, it is more important than ever that organizations have independent visibility and control over the integrity of their devices."

Fortunately, the researchers also noted that the attack would require redirecting a targeted machine’s traffic to servers hosting malware. That makes it unlikely to be used against random Dell users.

"As noted above, an attack scenario would require an attacker to be able to redirect the victim’s traffic, such as via a Machine-in-the-Middle (MITM) attack."

However, the researchers added, "the virtually unlimited control" over a device that this attack can provide makes it worth the effort by hackers.

Considering Dell size and reach, the four bugs could attract hackers who wish to target its “supply chain and support infrastructure.”