Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
High

CVE-2020-5344

Disclosure Date: March 26, 2020 (last updated February 21, 2025)
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.
Attacker Value
Unknown

CVE-2024-25943

Disclosure Date: June 29, 2024 (last updated February 04, 2025)
iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker could potentially exploit this vulnerability, leading to arbitrary code execution on the vulnerable application.
Attacker Value
Unknown

CVE-2022-34435

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.
Attacker Value
Unknown

CVE-2022-24422

Disclosure Date: May 11, 2022 (last updated February 23, 2025)
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console.
Attacker Value
Unknown

CVE-2021-36301

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system.
Attacker Value
Unknown

CVE-2021-36299

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to the affected application.
Attacker Value
Unknown

CVE-2021-36300

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability by sending a specially crafted malicious request to crash the webserver or cause information disclosure.
Attacker Value
Unknown

CVE-2021-21580

Disclosure Date: June 30, 2021 (last updated February 23, 2025)
Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.
Attacker Value
Unknown

CVE-2021-21579

Disclosure Date: June 30, 2021 (last updated February 23, 2025)
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.
Attacker Value
Unknown

CVE-2021-21581

Disclosure Date: June 30, 2021 (last updated February 23, 2025)
Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.