PT-2021-14622 · Dell Emc · Idrac9

Kajetan Rostojek

·

Published

2021-08-03

·

Updated

2021-08-09

·

CVE-2021-21576

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dell EMC iDRAC9 versions prior to 4.40.40.00
Description The issue is a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim's browser by tricking a victim into following a specially crafted link.
Recommendations For versions prior to 4.40.40.00, update to version 4.40.40.00 or later to resolve the issue. As a temporary workaround, consider restricting access to the iDRAC9 interface to minimize the risk of exploitation. Avoid following specially crafted links from untrusted sources to prevent potential attacks.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21576

Affected Products

Idrac9