Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:HDell Idrac7
HWDellwszystkie wersjeDell Idrac7 Firmware
OSDell< 2.65.65.65Dell Idrac8
HWDellwszystkie wersjeDell Idrac8 Firmware
OSDell< 2.70.70.70Dell Idrac9
HWDellwszystkie wersjeDell Idrac9 Firmware
OSDell< 4.00.00.00
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEMemory
Powiązane podatności
CVE-2022-24422CRITICAL9.6PL ✓ten sam produkt
Dell iDRAC9 — ominięcie uwierzytelnienia w konsoli VNC (Auth Bypass)
CVE-2021-21538CRITICAL9.6PL ✓ten sam produkt
Auth Bypass w Dell EMC iDRAC9 — dostęp do wirtualnej konsoli
CVE-2019-3705CRITICAL9.8PL ✓ten sam produkt
Stack-based buffer overflow w Dell EMC iDRAC6/7/8/9 — zdalny RCE
CVE-2024-25943HIGH7.6ten sam produkt
iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contai...
CVE-2024-25951HIGH8.0ten sam produkt
A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of...