QID 730751

Date Published: 2023-03-16

QID 730751: Dell iDRAC8 Denial of Service (DoS) Vulnerability (dsa-2022-069)

The integrated Dell Remote Access Controller (iDRAC) provides functionality that helps IT administrators deploy, update, monitor, and maintain Dell servers.

Affected Versions:
Dell iDRAC8 versions prior to 2.83.83.83
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Dell iDRAC by sending a GET request to "session?aimGetProp=fwVersionFull" endpoint. Please note that this QID requires ML-12.3.4 or later.

A remote unauthenticated attacker could potentially exploit this vulnerability to cause resource exhaustion in the webserver, resulting in a denial of service condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer dsa-2022-069 advisory for latest updates

    CVEs related to QID 730751

    Software Advisories
    Advisory ID Software Component Link
    dsa-2022-069 URL Logo www.dell.com/support/kbdoc/en-in/000198064/dsa-2022-069