CVE-2019-3705
Summary
| CVE | CVE-2019-3705 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-26 19:29:00 UTC |
| Updated | 2020-10-16 18:04:00 UTC |
| Description | Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or execute arbitrary code on the system with privileges of the webserver by sending specially crafted input data to the affected system. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Dell | Idrac6 Firmware | All | All | All | All |
| Operating System | Dell | Idrac6 Firmware | All | All | All | All |
| Operating System | Dell | Idrac7 Firmware | All | All | All | All |
| Operating System | Dell | Idrac7 Firmware | All | All | All | All |
| Operating System | Dell | Idrac8 Firmware | All | All | All | All |
| Operating System | Dell | Idrac8 Firmware | All | All | All | All |
| Operating System | Dell | Idrac9 Firmware | All | All | All | All |
| Operating System | Dell | Idrac9 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DSA-2019-028: Dell EMC iDRAC Multiple Vulnerabilities | Dell US | MISC | www.dell.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.