Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDell Idrac7
HWDellall versionsDell Idrac7 Firmware
OSDell≤ 2.30.30.30Dell Idrac8
HWDellall versionsDell Idrac8 Firmware
OSDell≤ 2.30.30.30
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-3705CRITICAL9.8PL ✓same product
Stack-based buffer overflow w Dell EMC iDRAC6/7/8/9 — zdalny RCE
CVE-2024-25951HIGH8.0same product
A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of...
CVE-2020-5344HIGH7.0same product
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based ...
CVE-2018-1243HIGH7.5same product
Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prio...
CVE-2018-1244HIGH8.8same product
Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a comman...