QID 731050

QID 731050: Dell EMC iDRAC9 Cross-Site Scripting (XSS) Vulnerability (DSA-2021-073)

The integrated Dell Remote Access Controller (iDRAC) provides functionality that helps IT administrators deploy, update, monitor, and maintain Dell servers.

Affected Versions:
Dell iDRAC 9 prior to version 4.40.10.00
QID Detection Logic (Unauthenticated):
This QID tries to find vulnerable Dell stack-based buffer overflow iDRAC versions by transmitting a HTTP GET request to public/about.html,sysmgmt/2015/bmc/info and aimGetProp=fwVersionFull.

A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected while generating a certificate.

  • CVSS V3 rated as Medium - 4.8 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to update to Dell iDRAC 4.40.10.00

    CVEs related to QID 731050

    Software Advisories
    Advisory ID Software Component Link
    dsa-2021-073 URL Logo www.dell.com/support/kbdoc/en-in/000185293/dsa-2021-073-dell-emc-idrac-9-security-update-for-multiple-vulnerabilities