QID 731050
QID 731050: Dell EMC iDRAC9 Cross-Site Scripting (XSS) Vulnerability (DSA-2021-073)
The integrated Dell Remote Access Controller (iDRAC) provides functionality that helps IT administrators deploy, update, monitor, and maintain Dell servers.
Affected Versions:
Dell iDRAC 9 prior to version 4.40.10.00
QID Detection Logic (Unauthenticated):
This QID tries to find vulnerable Dell stack-based buffer overflow iDRAC versions by transmitting a HTTP GET request to public/about.html,sysmgmt/2015/bmc/info and aimGetProp=fwVersionFull.
A remote authenticated malicious user with high privileges may potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected while generating a certificate.
Solution
Customers are advised to update to Dell iDRAC 4.40.10.00
Vendor References
CVEs related to QID 731050
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| dsa-2021-073 |
|