Back to Database
Status published
High
CVE-2021-28216
BootPerformanceTable pointer is read from an NVRAM variable in PEI....
Vulnerability Description
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-28216
Credits & Attribution
No credits recorded in the NVD database.
More from TianoCore
View All →CVE-2025-3770
SMM IDT Privilege Escalation Vulnerability
High
7
CVE-2025-2296
Un-verified kernel bypass Secure Boot mechanism in direct boot mode
High
8.4
CVE-2025-2295
Potential iSCSI R2T PDU Vulnerability
Low
3.5
CVE-2024-38805
iSCSI Remote Memory Corruption and Denial of Service
Medium
6.3
CVE-2024-38798
Uncleared password keystrokes in circular queue can lead to information disclosure or escalation of privilege
Medium
5.8
Affected Vendor
TianoCore
View all reports →Affected Software
EDK II
Vulnerable Versions:
EDK II Master
Timeline
Official Publish:
August 5th, 2021
Last Modified:
November 3rd, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.