MEDIUM🇵🇱 Wersja polska

CVE-2020-26198

CVSS 6.1v3.1pub. 2020-12-16upd. 2024-11-21

Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Dell Idrac9

    HW
    Dell
    all versions
  • Dell Idrac9 Firmware

    OS
    Dell
    4.40.00.00≤ 4.32.10.00
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2022-24422CRITICAL9.6PL ✓same product

Dell iDRAC9 — ominięcie uwierzytelnienia w konsoli VNC (Auth Bypass)

CVE-2021-21538CRITICAL9.6PL ✓same product

Auth Bypass w Dell EMC iDRAC9 — dostęp do wirtualnej konsoli

CVE-2019-3705CRITICAL9.8PL ✓same product

Stack-based buffer overflow w Dell EMC iDRAC6/7/8/9 — zdalny RCE

CVE-2024-25943HIGH7.6same product

iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contai...

CVE-2020-5366HIGH7.1same product

Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated ma...