CVE-2013-3589
Summary
| CVE | CVE-2013-3589 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-09-24 10:35:00 UTC |
| Updated | 2013-09-25 17:52:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Dell | Idrac6 Firmware | 1.0 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.1 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.2 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.3 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.5 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.6 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.8 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.0 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.1 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.2 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.3 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.5 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.6 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.8 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | All | All | All | All |
| Hardware | Dell | Idrac6 Monolithic | - | All | All | All |
| Hardware | Dell | Idrac6 Monolithic | - | All | All | All |
| Hardware | Dell | Idrac7 | - | All | All | All |
| Hardware | Dell | Idrac7 | - | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.00.00 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.06.06 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.10.10 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.20.20 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.23.23 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.37.35 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.00.00 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.06.06 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.10.10 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.20.20 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.23.23 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.37.35 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#920038 - Dell iDRAC 6 and iDRAC 7 are vulnerable to a cross-site scripting (XSS) attack | CERT-VN | www.kb.cert.org | US Government Resource |
| VU#920038 - Dell iDRAC 6 and iDRAC 7 are vulnerable to a cross-site scripting (XSS) attack | CONFIRM | www.kb.cert.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.