Known Vulnerabilities for Idrac7 Firmware by Dell
Listed below are 9 of the newest known vulnerabilities associated with "Idrac7 Firmware" by "Dell".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-5344 | Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow... | 9.8 - CRITICAL | 2020-03-31 | 2020-04-03 |
| CVE-2019-3764 | Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 con... | 4.3 - MEDIUM | 2019-11-07 | 2020-10-16 |
| CVE-2019-3705 | Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, ... | 9.8 - CRITICAL | 2019-04-26 | 2020-10-16 |
| CVE-2018-15776 | Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated atta... | 6.8 - MEDIUM | 2018-12-13 | 2020-08-24 |
| CVE-2018-15774 | Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23... | 8.8 - HIGH | 2018-12-13 | 2019-10-09 |
| CVE-2018-1244 | Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vul... | 8.8 - HIGH | 2018-07-02 | 2019-10-09 |
| CVE-2018-1243 | Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21... | 7.5 - HIGH | 2018-07-02 | 2019-10-09 |
| CVE-2016-5685 | Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a ... | 8.8 - HIGH | 2016-11-29 | 2016-12-01 |
| CVE-2013-3589 | Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devi... | 4.3 - MEDIUM | 2013-09-24 | 2013-09-25 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Dell | Idrac7 Firmware | 2.61.60.60 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.40.40 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.37.35 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.23.23 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.20.20 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.10.10 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.06.06 | All | All | All |
| Operating System | Dell | Idrac7 Firmware | 1.00.00 | All | All | All |