HIGH🇵🇱 Wersja polska

CVE-2020-5344

CVSS 7.0v3.1pub. 2020-03-31upd. 2024-11-21

Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
  • Dell Idrac7

    HW
    Dell
    all versions
  • Dell Idrac7 Firmware

    OS
    Dell
    < 2.65.65.65
  • Dell Idrac8

    HW
    Dell
    all versions
  • Dell Idrac8 Firmware

    OS
    Dell
    < 2.70.70.70
  • Dell Idrac9

    HW
    Dell
    all versions
  • Dell Idrac9 Firmware

    OS
    Dell
    < 4.00.00.00
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2022-24422CRITICAL9.6PL ✓same product

Dell iDRAC9 — ominięcie uwierzytelnienia w konsoli VNC (Auth Bypass)

CVE-2021-21538CRITICAL9.6PL ✓same product

Auth Bypass w Dell EMC iDRAC9 — dostęp do wirtualnej konsoli

CVE-2019-3705CRITICAL9.8PL ✓same product

Stack-based buffer overflow w Dell EMC iDRAC6/7/8/9 — zdalny RCE

CVE-2024-25943HIGH7.6same product

iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contai...

CVE-2024-25951HIGH8.0same product

A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of...