PT-2020-16336 · Dell Emc · Idrac9
Published
2020-12-16
·
Updated
2020-12-22
·
CVE-2020-26198
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dell EMC iDRAC9 versions prior to 4.32.10.00
Dell EMC iDRAC9 versions prior to 4.40.00.00
Description
The issue is a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this to run malicious HTML or JavaScript in a victim’s browser by tricking a victim into following a specially crafted link.
Recommendations
For versions prior to 4.32.10.00, update to version 4.32.10.00 or later.
For versions prior to 4.40.00.00, update to version 4.40.00.00 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Idrac9