Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NDell Idrac9
HWDellall versionsDell Idrac9 Firmware
OSDell4.40.00.00≤ 4.32.10.00
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
Related vulnerabilities
CVE-2022-24422CRITICAL9.6PL ✓same product
Dell iDRAC9 — ominięcie uwierzytelnienia w konsoli VNC (Auth Bypass)
CVE-2021-21538CRITICAL9.6PL ✓same product
Auth Bypass w Dell EMC iDRAC9 — dostęp do wirtualnej konsoli
CVE-2019-3705CRITICAL9.8PL ✓same product
Stack-based buffer overflow w Dell EMC iDRAC6/7/8/9 — zdalny RCE
CVE-2024-25943HIGH7.6same product
iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contai...
CVE-2020-5366HIGH7.1same product
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated ma...