PT-2018-1455 · Dell Emc · Idrac8+2
Publicado
2018-07-02
·
Atualizado
2019-10-09
·
CVE-2018-1244
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dell EMC iDRAC7 versions prior to 2.60.60.60
Dell EMC iDRAC8 versions prior to 2.60.60.60
Dell EMC iDRAC9 versions prior to 3.21.21.21
Description
The issue is related to a command injection vulnerability in the SNMP agent of the affected iDRAC versions. A remote authenticated malicious user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC where SNMP alerting is enabled. The vulnerability is associated with the injection or modification of an argument, allowing a remote attacker to execute arbitrary commands.
Recommendations
For Dell EMC iDRAC7 versions prior to 2.60.60.60, update to version 2.60.60.60 or later to resolve the issue.
For Dell EMC iDRAC8 versions prior to 2.60.60.60, update to version 2.60.60.60 or later to resolve the issue.
For Dell EMC iDRAC9 versions prior to 3.21.21.21, update to version 3.21.21.21 or later to resolve the issue.
Correção
Command Injection
Argument Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Idrac7
Idrac8
Idrac9