QID 731241
Date Published: 2024-03-20
QID 731241: Dell iDRAC8 Command Injection Vulnerability (DSA-2024-089)
The integrated Dell Remote Access Controller (iDRAC) provides functionality that helps IT administrators deploy, update, monitor, and maintain Dell servers.
CVE-2024-25951: A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.
Affected Versions:
Dell iDRAC8 versions prior to 2.85.85.85
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Dell iDRAC by sending a GET request to "session?aimGetProp=fwVersionFull" endpoint.
Note: This QID requires ML-12.3.4 or later.
Successful exploitation of this vulnerability may allow authenticated attacker to potentially exploit this vulnerability to gain control of the underlying operating system.
- DSA-2024-089 -
www.dell.com/support/kbdoc/en-us/000222591/
CVEs related to QID 731241
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| DSA-2024-089 |
|