QID 731047
Date Published: 2023-12-27
QID 731047: Dell EMC iDRAC9 Improper Input Validation Vulnerability (DSA-2021-177)
The integrated Dell Remote Access Controller (iDRAC) provides functionality that helps IT administrators deploy, update, monitor, and maintain Dell servers.
Affected Versions:
Dell iDRAC 9 prior to version 5.00.00.00
QID Detection Logic (Unauthenticated):
This QID tries to find vulnerable Dell stack-based buffer overflow iDRAC versions by transmitting a HTTP GET request to public/about.html,sysmgmt/2015/bmc/info and aimGetProp=fwVersionFull.
Successful exploitation of this vulnerability may crash the webserver
Solution
Customers are advised to update to Dell iDRAC 5.00.00.00
Vendor References
CVEs related to QID 731047
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| dsa-2021-177 |
|