PT-2018-1455 · Dell Emc · Idrac8+2

Publicado

2018-07-02

·

Atualizado

2019-10-09

·

CVE-2018-1244

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell EMC iDRAC7 versions prior to 2.60.60.60 Dell EMC iDRAC8 versions prior to 2.60.60.60 Dell EMC iDRAC9 versions prior to 3.21.21.21
Description The issue is related to a command injection vulnerability in the SNMP agent of the affected iDRAC versions. A remote authenticated malicious user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC where SNMP alerting is enabled. The vulnerability is associated with the injection or modification of an argument, allowing a remote attacker to execute arbitrary commands.
Recommendations For Dell EMC iDRAC7 versions prior to 2.60.60.60, update to version 2.60.60.60 or later to resolve the issue. For Dell EMC iDRAC8 versions prior to 2.60.60.60, update to version 2.60.60.60 or later to resolve the issue. For Dell EMC iDRAC9 versions prior to 3.21.21.21, update to version 3.21.21.21 or later to resolve the issue.

Correção

Command Injection

Argument Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01006
CVE-2018-1244

Produtos afetados

Idrac7
Idrac8
Idrac9