CVE-2013-3589
Summary
| CVE | CVE-2013-3589 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-09-24 10:35:51 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Dell | Idrac6 Firmware | 1.0 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.1 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.2 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.3 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.5 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.6 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | 1.8 | All | All | All |
| Operating System | Dell | Idrac6 Firmware | All | All | All | All |
| Hardware | Dell | Idrac6 Monolithic | - | All | All | All |
| Hardware | Dell | Idrac7 | - | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.00.00 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.06.06 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.10.10 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.20.20 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.23.23 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.37.35 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#920038 - Dell iDRAC 6 and iDRAC 7 are vulnerable to a cross-site scripting (XSS) attack | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| VU#920038 - Dell iDRAC 6 and iDRAC 7 are vulnerable to a cross-site scripting (XSS) attack | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.