PT-2021-21206 · Dell+1 · Idrac9+1

Published

2021-09-09

·

Updated

2021-11-27

·

CVE-2021-36299

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Dell iDRAC9 versions 4.40.00.00 through 4.40.28.00 Dell iDRAC9 version 5.00.00.00 is not affected, the issue is present in versions prior to 4.40.29.00
Description The issue is an SQL injection vulnerability that can be exploited by a remote authenticated malicious user with low privileges. This can be done by supplying specially crafted input data to the affected application, potentially causing information disclosure or denial of service.
Recommendations For Dell iDRAC9 versions 4.40.00.00 through 4.40.28.00, update to version 4.40.29.00 or later to resolve the issue. For Dell iDRAC9 versions prior to 4.40.29.00, consider restricting access to the affected application as a temporary workaround until a patch is available.

Fix

DoS

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36299

Affected Products

Check Point Gaia
Idrac9