PT-2018-1455 · Dell Emc · Idrac8+2

Published

2018-07-02

·

Updated

2019-10-09

·

CVE-2018-1244

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell EMC iDRAC7 versions prior to 2.60.60.60 Dell EMC iDRAC8 versions prior to 2.60.60.60 Dell EMC iDRAC9 versions prior to 3.21.21.21
Description The issue is related to a command injection vulnerability in the SNMP agent of the affected iDRAC versions. A remote authenticated malicious user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC where SNMP alerting is enabled. The vulnerability is associated with the injection or modification of an argument, allowing a remote attacker to execute arbitrary commands.
Recommendations For Dell EMC iDRAC7 versions prior to 2.60.60.60, update to version 2.60.60.60 or later to resolve the issue. For Dell EMC iDRAC8 versions prior to 2.60.60.60, update to version 2.60.60.60 or later to resolve the issue. For Dell EMC iDRAC9 versions prior to 3.21.21.21, update to version 3.21.21.21 or later to resolve the issue.

Fix

Command Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01006
CVE-2018-1244

Affected Products

Idrac7
Idrac8
Idrac9