HIGH🇬🇧 English

CVE-2020-5344

CVSS 7.0v3.1pub. 2020-03-31upd. 2024-11-21

Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
  • Dell Idrac7

    HW
    Dell
    wszystkie wersje
  • Dell Idrac7 Firmware

    OS
    Dell
    < 2.65.65.65
  • Dell Idrac8

    HW
    Dell
    wszystkie wersje
  • Dell Idrac8 Firmware

    OS
    Dell
    < 2.70.70.70
  • Dell Idrac9

    HW
    Dell
    wszystkie wersje
  • Dell Idrac9 Firmware

    OS
    Dell
    < 4.00.00.00
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEMemory
CWE
Referencje

Powiązane podatności

CVE-2022-24422CRITICAL9.6PL ✓ten sam produkt

Dell iDRAC9 — ominięcie uwierzytelnienia w konsoli VNC (Auth Bypass)

CVE-2021-21538CRITICAL9.6PL ✓ten sam produkt

Auth Bypass w Dell EMC iDRAC9 — dostęp do wirtualnej konsoli

CVE-2019-3705CRITICAL9.8PL ✓ten sam produkt

Stack-based buffer overflow w Dell EMC iDRAC6/7/8/9 — zdalny RCE

CVE-2024-25943HIGH7.6ten sam produkt

iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contai...

CVE-2024-25951HIGH8.0ten sam produkt

A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of...