QID 730171

Date Published: 2021-09-02

QID 730171: Dell EMC iDRAC multiple Vulnerabilities (DSA-2021-073) -iDRAC 9

The integrated Dell Remote Access Controller (iDRAC) provides functionality that helps IT administrators deploy, update, monitor, and maintain Dell servers.

Dell EMC iDRAC9 versions prior to 4.40.00.00 contain multiple stored cross-site scripting vulnerabilities.
Affected Versions:
Dell EMC iDRAC9 versions prior to 4.40.00.00

QID Detection Logic (Unauthenticated):
This QID tries to find vulnerable Dell EMC iDRAC versions by transmitting a HTTP GET request to public/about.html,sysmgmt/2015/bmc/info and aimGetProp=fwVersionFull.

A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected parameters. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    Customers are advised to update to Dell EMC iDRAC6 versions prior to 4.40.00.00 or later to remediate these vulnerabilities.
    Software Advisories
    Advisory ID Software Component Link
    DSA-2021-073 URL Logo www.dell.com/support/kbdoc/en-in/000185293/dsa-2021-073-dell-emc-idrac-9-security-update-for-multiple-vulnerabilities