Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:HDell Idrac7
HWDellall versionsDell Idrac7 Firmware
OSDell< 2.65.65.65Dell Idrac8
HWDellall versionsDell Idrac8 Firmware
OSDell< 2.70.70.70Dell Idrac9
HWDellall versionsDell Idrac9 Firmware
OSDell< 4.00.00.00
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
Related vulnerabilities
CVE-2022-24422CRITICAL9.6PL ✓same product
Dell iDRAC9 — ominięcie uwierzytelnienia w konsoli VNC (Auth Bypass)
CVE-2021-21538CRITICAL9.6PL ✓same product
Auth Bypass w Dell EMC iDRAC9 — dostęp do wirtualnej konsoli
CVE-2019-3705CRITICAL9.8PL ✓same product
Stack-based buffer overflow w Dell EMC iDRAC6/7/8/9 — zdalny RCE
CVE-2024-25943HIGH7.6same product
iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contai...
CVE-2024-25951HIGH8.0same product
A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of...