QID 731052

Date Published: 2024-01-16

QID 731052: Dell EMC iDRAC Open Secure Sockets Layer (OpenSSL) Vulnerability (DSA-2022-154)

The integrated Dell Remote Access Controller (iDRAC) provides functionality that helps IT administrators deploy, update, monitor, and maintain Dell servers.

Affected Versions:
Dell iDRAC 9 prior to version 5.10.30.00
Dell iDRAC 8 prior to version 2.83.83.83
QID Detection Logic (Unauthenticated):
This QID tries to find vulnerable Dell stack-based buffer overflow iDRAC versions by transmitting a HTTP GET request to public/about.html,sysmgmt/2015/bmc/info and aimGetProp=fwVersionFull.

Successful exploitation may compromise the system

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to update to Dell iDRAC8 2.83.83.83 and iDRAC9 5.10.30.00

    CVEs related to QID 731052

    Software Advisories
    Advisory ID Software Component Link
    dsa-2022-154 URL Logo www.dell.com/support/kbdoc/en-us/000200644/dsa-2022-154-dell-idrac8-and-dell-idrac9-security-update-for-an-openssl-vulnerability