PT-2018-1455 · Dell Emc · Idrac8+2
Published
2018-07-02
·
Updated
2019-10-09
·
CVE-2018-1244
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dell EMC iDRAC7 versions prior to 2.60.60.60
Dell EMC iDRAC8 versions prior to 2.60.60.60
Dell EMC iDRAC9 versions prior to 3.21.21.21
Description
The issue is related to a command injection vulnerability in the SNMP agent of the affected iDRAC versions. A remote authenticated malicious user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC where SNMP alerting is enabled. The vulnerability is associated with the injection or modification of an argument, allowing a remote attacker to execute arbitrary commands.
Recommendations
For Dell EMC iDRAC7 versions prior to 2.60.60.60, update to version 2.60.60.60 or later to resolve the issue.
For Dell EMC iDRAC8 versions prior to 2.60.60.60, update to version 2.60.60.60 or later to resolve the issue.
For Dell EMC iDRAC9 versions prior to 3.21.21.21, update to version 3.21.21.21 or later to resolve the issue.
Fix
Command Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Idrac7
Idrac8
Idrac9