Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
High
CVE-2020-5344
Disclosure Date: March 26, 2020 (last updated February 21, 2025)
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.
2
Attacker Value
Moderate
CVE-2018-1207
Disclosure Date: March 23, 2018 (last updated November 26, 2024)
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.
2
Attacker Value
Low
CVE-2018-1211
Disclosure Date: March 23, 2018 (last updated November 26, 2024)
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI parser which could be used to obtain specific sensitive data without authentication. A remote unauthenticated attacker may be able to read configuration settings from the iDRAC by querying specific URI strings.
2
Attacker Value
Unknown
CVE-2024-3411
Disclosure Date: April 30, 2024 (last updated July 03, 2024)
Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, allowing an attacker to use either predictable IPMI Session ID or weak BMC Random Number to bypass security controls using spoofed IPMI packets to manage BMC device.
0
Attacker Value
Unknown
CVE-2024-25951
Disclosure Date: March 09, 2024 (last updated February 01, 2025)
A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.
0
Attacker Value
Unknown
CVE-2022-34436
Disclosure Date: January 18, 2023 (last updated November 08, 2023)
Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.
0
Attacker Value
Unknown
CVE-2021-36301
Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system.
0
Attacker Value
Unknown
CVE-2021-21580
Disclosure Date: June 30, 2021 (last updated February 23, 2025)
Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.
0
Attacker Value
Unknown
CVE-2021-21510
Disclosure Date: March 04, 2021 (last updated February 22, 2025)
Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.
0
Attacker Value
Unknown
CVE-2019-3764
Disclosure Date: November 07, 2019 (last updated November 27, 2024)
Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as password hashes.
0