Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvg3-9cx3-qjv5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.

EPSS

Процентиль: 61%
0.00415
Низкий

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 5.9
nvd
почти 5 лет назад

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.

EPSS

Процентиль: 61%
0.00415
Низкий

Дефекты

CWE-367