QID 730282

Date Published: 2021-11-25

QID 730282: Dell EMC iDRAC Authentication Bypass Vulnerability (DSA-2021-082) -iDRAC 9

The integrated Dell Remote Access Controller (iDRAC) provides functionality that helps IT administrators deploy, update, monitor, and maintain Dell servers.

Dell EMC iDRAC9 versions from 4.40.00.00 prior to 4.40.10.00 may allow remote unauthenticated attacker could potentially exploit an improper authentication vulnerability to gain access to the virtual console.
Affected Versions:
Dell EMC iDRAC9 from 4.40.00.00 prior to 4.40.10.00

QID Detection Logic (Unauthenticated):
This QID tries to find vulnerable Dell EMC iDRAC versions by transmitting a HTTP GET request to public/about.html,sysmgmt/2015/bmc/info

Successful exploitation of this vulnerability may allow a remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the virtual console.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to update to Dell EMC versions 4.40.10.00 or later to remediate these vulnerabilities.

    CVEs related to QID 730282

    Software Advisories
    Advisory ID Software Component Link
    DSA-2021-082 URL Logo www.dell.com/support/kbdoc/en-in/000186420/dsa-2021-082-dell-emc-idrac-9-security-update-for-improper-authentication-vulnerability