Evidence dossier
CVE-2021-21551
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure.
Exploited in the wild (CISA KEV since Mar 31, 2022). NVD reports CVSS 3.1 7.8. Severity assessments differ within at least one CVSS version. EPSS estimates 79.2% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
- State
- PUBLISHED
- Published
- May 4, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 80%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAdellOriginal evidence ↗
Record text: Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
Inspect raw assertion
- Field
container- Value
- Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Dell dbutil Driver Insufficient Access Control Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Dell dbutil Driver Insufficient Access Control Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 79.25% probability · 99.57th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.792490000000; percentile 0.995690000000
Assessments differ
Values are shown separately by source and CVSS version.
CISA KEV · catalog date Mar 31, 2022 · first observed Jul 19, 2026
FIRST EPSS · score date Aug 27, 2026 · 99.6th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · values shown separately below
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible assertions materially conflict and remain visible side by side.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve conflict
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
Inspect raw assertion
- Field
container- Value
- Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
Dell dbutil Driver Insufficient Access Control Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Dell dbutil Driver Insufficient Access Control Vulnerability
79.25% probability · 99.57th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.792490000000; percentile 0.995690000000
Applicability
Cited product scope
Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
This CVE has more than 500 applicability assertions. The returned evidence is deterministically capped; the summary counts cover the complete snapshot.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
501 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.3"}]product-37c4e1b349d7e584dec36b1903e750229ef69ad101ce0f4d43b2350d11ebd7ddLinked exactInspect raw assertion
cpe:2.3:h:dell:alienware_14:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a3bdd0f0-b3d1-45dc-b1ca-24f17c291b71
product-b8e0333eb43c8028d377ec25a7f6dc4332a7c1a4f80107ed2636277629853b83Linked exactInspect raw assertion
cpe:2.3:h:dell:alienware_17_51m_r2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eb791fab-8e62-4ba1-ac0d-d8f22e13861b
product-ed925331f5204362813de5e9b4fb8994a694afd76af9df5491ed9532cd312fc1Linked exactInspect raw assertion
cpe:2.3:h:dell:alienware_area_51:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
61ba47e8-dc8c-465b-ac52-956a003b80c6
product-c6e2be541cec8d7ba9db297afd70a24ca91f6b61dae62a6690083705cbd15461Linked exactInspect raw assertion
cpe:2.3:h:dell:alienware_asm100:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4c3128dd-9a90-4863-a693-a6d5e46b797e
product-a09d6a4566619ce6778821cba46573f8f4dd25a2986ef4cb44ab3b3742d7f18dLinked exactInspect raw assertion
cpe:2.3:h:dell:alienware_asm100r2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
70aed9b9-fc76-41b0-ac24-2b51ff1e1ebc
product-d2c120f3244aef981efc6d995e8ca20f45e08e0f1a311b2c028ac45fb3a67452Linked exactInspect raw assertion
cpe:2.3:h:dell:alienware_m14xr2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
39e33acf-06d0-4f77-91d6-bd3f7a8b1363
product-3e1531bdc7152e9df2b5a7b06745c990ad8865d13d54de461216012a90058ba7Linked exactInspect raw assertion
cpe:2.3:h:dell:alienware_m15_r4:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b084185f-1c0d-47d9-9f72-a79095462428
product-ac5bfca539153d3f27a21e78972d929ed15df3d0db30c8148945ff7b21dd454dLinked exactInspect raw assertion
cpe:2.3:h:dell:alienware_m17xr4:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9ca3fe0d-2ecb-49f7-a2a3-8c7927cf61d2
product-5454a1bd3d97885ac734743e82bb5e10893cfeddd979b1739e06883ffc5d0ae4Linked exactInspect raw assertion
cpe:2.3:h:dell:alienware_m18xr2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
50daade9-d885-4c56-bcb5-ffab10083a12
product-a87e1bf0b78d6b4455038bb3216fc317bcc41f573d9259139b8291eaf0040d56Linked exactInspect raw assertion
cpe:2.3:h:dell:canvas_27:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b2b43435-21ba-4c2e-b8a0-e6bc90fc0f89
product-287561fb5d634ab88c42bcc9608242799d6f1c04ee72148a872433f767f75128Linked exactInspect raw assertion
cpe:2.3:h:dell:cheng_ming_3967:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
af88aed3-7c7b-4cac-8d17-9a5427821e37
product-8cdbe493267da31494ee7927ff7c087af2554be4b733dda155c6cee25e0ec57eLinked exactInspect raw assertion
cpe:2.3:h:dell:chengming_3977:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
67fcce7c-bac7-43f2-b328-c3afd80b6af0
product-045de1c559e0bb24f1b8ab903c4a290e35e2ea74cb2ec4555a94d1040cbdcc77Linked exactInspect raw assertion
cpe:2.3:h:dell:chengming_3988:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c83a9845-dbeb-4d97-a9f3-71d0262d4a6f
product-a529087fbb547735a0f31a4b699be0415e0b32a16601ce3ef5b851508c36591eLinked exactInspect raw assertion
cpe:2.3:h:dell:chengming_3991:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d8e9396f-11fc-43bc-be74-b5fa7954a0ce
product-e4c927e594b8d483693b7eec1d61f1813de19318caf4c222928f7aac16fbbc94Linked exactInspect raw assertion
cpe:2.3:a:dell:dbutil:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 2.3
- Match ID
2bfe61fd-9349-4afa-847c-b1047d55770c
product-c071bbe3c2fe5d9dcd2333f193d00f5648239b9051c40ffb659df1aaff238804Linked exactInspect raw assertion
cpe:2.3:h:dell:dock_wd15:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f66dcd8a-17aa-4db7-9ad1-46e04916ee66
product-1b5d14bb773eec463ea96e5ece96c0f614ef962b510dd577e7f72b25e1ac0f1cLinked exactInspect raw assertion
cpe:2.3:h:dell:dock_wd19:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
15124df5-16f4-45fd-94cb-9dbbda9d7944
product-ce20b2ea80ea21031cfac4114ded7258d0977cb5cf083c763909c2ef958b49c0Linked exactInspect raw assertion
cpe:2.3:h:dell:embedded_box_pc_5000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f7b2be27-f109-4b11-8e8b-732a1ae3cc2f
product-61f2922cddad956796ce2f0c79c30c72352f9500f11d3470d6f2823869e72eceLinked exactInspect raw assertion
cpe:2.3:h:dell:g15_5510:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ae6c4737-dad8-4921-b65c-8d11669b730d
product-41d30a373e4bf3b2246323f6accbc5fbcb4f377255515087f0f4832bd5abaa9aLinked exactInspect raw assertion
cpe:2.3:h:dell:g3_3500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
79c0e8d8-fe8f-4718-8837-8c8fcacdb095
product-df36a074932802354d4d91c96d541c218ae8a83dd31489de9a2154cfa8c9eebbLinked exactInspect raw assertion
cpe:2.3:h:dell:g3_3579:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2f440e47-2c2a-4ea2-a799-649a23145d51
product-80aa4c1b723f1693e1ac3b9c8f682d0d5350b90513f256c1405d2167743ab479Linked exactInspect raw assertion
cpe:2.3:h:dell:g3_3779:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
598a90e5-c7ae-4901-bd33-375f88cf09c4
product-afcd1a7ca860c4cdb2e38b86697ba94ccd6df83f6cb340fcd63f6deb4e701cfeLinked exactInspect raw assertion
cpe:2.3:h:dell:g5_5000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b49a7e9-ea33-4614-b91d-465d32407be3
product-4c825526ef57d5dba635f0fe97f02d7fd9ed91dbbb67ec6d1c25809a0ec56182Linked exactInspect raw assertion
cpe:2.3:h:dell:g5_5500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
81a8617f-56b1-4998-98cc-fa8c1d3de011
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-672f7be6cef424a0fe9d0805383bdc16e8f97d7201e4086c9232a0a4cd55bd8d · product-e4c927e594b8d483693b7eec1d61f1813de19318caf4c222928f7aac16fbbc94
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
55c12c3a-0cb9-4b23-bb0a-c39eee110cc4Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fb0593ce-3e1e-4d5f-a7b8-52029cda5de8Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV:L/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDirect CVE/CNA normalized decisions
dell
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 8.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.