QID 731048
Date Published: 2024-01-16
QID 731048: Dell EMC iDRAC Multiple Vulnerabilities (DSA-2022-265)
The integrated Dell Remote Access Controller (iDRAC) provides functionality that helps IT administrators deploy, update, monitor, and maintain Dell servers.
Affected Versions:
Dell iDRAC 9 prior to version 6.00.30.00
Dell iDRAC 8 prior to version 2.84.84.84
QID Detection Logic (Unauthenticated):
This QID tries to find vulnerable Dell stack-based buffer overflow iDRAC versions by transmitting a HTTP GET request to public/about.html,sysmgmt/2015/bmc/info and aimGetProp=fwVersionFull.
A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.
Solution
Customers are advised to update to Dell iDRAC 6.00.30.00 and Dell iDRAC8 2.84.84.84
Vendor References
CVEs related to QID 731048
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| dsa-2022-265 |
|