PT-2021-21206 · Dell+1 · Idrac9+1
Published
2021-09-09
·
Updated
2021-11-27
·
CVE-2021-36299
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Dell iDRAC9 versions 4.40.00.00 through 4.40.28.00
Dell iDRAC9 version 5.00.00.00 is not affected, the issue is present in versions prior to 4.40.29.00
Description
The issue is an SQL injection vulnerability that can be exploited by a remote authenticated malicious user with low privileges. This can be done by supplying specially crafted input data to the affected application, potentially causing information disclosure or denial of service.
Recommendations
For Dell iDRAC9 versions 4.40.00.00 through 4.40.28.00, update to version 4.40.29.00 or later to resolve the issue.
For Dell iDRAC9 versions prior to 4.40.29.00, consider restricting access to the affected application as a temporary workaround until a patch is available.
Fix
DoS
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Check Point Gaia
Idrac9