Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21539

Опубликовано: 30 апр. 2021
Источник: nvd
CVSS3: 5.9
CVSS3: 7.1
CVSS2: 4.6
EPSS Низкий

Описание

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:dell:idrac9_firmware:*:*:*:*:*:*:*:*
Версия до 4.40.00.00 (исключая)

EPSS

Процентиль: 61%
0.00415
Низкий

5.9 Medium

CVSS3

7.1 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-367

Связанные уязвимости

github
больше 3 лет назад

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.

EPSS

Процентиль: 61%
0.00415
Низкий

5.9 Medium

CVSS3

7.1 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-367