Описание
iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the iDRAC operating system.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.82.82.82 (исключая)
Одновременно
cpe:2.3:o:dell:integrated_dell_remote_access_controller_8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:integrated_dell_remote_access_controller_8:-:*:*:*:*:*:*:*
Конфигурация 2Версия до 5.00.20.00 (исключая)
Одновременно
cpe:2.3:o:dell:integrated_dell_remote_access_controller_9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:integrated_dell_remote_access_controller_9:-:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.03741
Низкий
6.2 Medium
CVSS3
7.2 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-121
CWE-787
Связанные уязвимости
github
около 4 лет назад
iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the iDRAC operating system.
EPSS
Процентиль: 88%
0.03741
Низкий
6.2 Medium
CVSS3
7.2 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-121
CWE-787