QID 731057

QID 731057: Dell EMC iDRAC9 Reflected Cross-Site Scripting (XSS) Vulnerability (DSA-2020-268)

The integrated Dell Remote Access Controller (iDRAC) provides functionality that helps IT administrators deploy, update, monitor, and maintain Dell servers.

Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application.

Affected Versions:
From Dell iDRAC-9 version 3.0x Series prior to version 4.32.10.00
From Dell iDRAC-9 version 4.33.10.00 prior to version 4.40.00.00
QID Detection Logic (Unauthenticated):
This QID tries to find vulnerable Dell stack-based buffer overflow iDRAC versions by transmitting a HTTP GET request to public/about.html,sysmgmt/2015/bmc/info and aimGetProp=fwVersionFull.

A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victims browser by tricking a victim in to following a specially crafted link.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to update to Dell iDRAC9 4.32.10.00 and iDRAC9 4.40.00.00

    CVEs related to QID 731057

    Software Advisories
    Advisory ID Software Component Link
    dsa-2020-268 URL Logo www.dell.com/support/kbdoc/en-us/000181088/dsa-2020-268-dell-emc-idrac9-reflected-xss-vulnerability