PT-2024-5579 · Dell · Dell Idrac Service Module

Published

2024-07-31

·

Updated

2024-08-02

·

CVE-2024-38490

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell iDRAC Service Module versions 5.3.0.0 and prior
Description The issue is related to an out of bound write vulnerability. A privileged local attacker could execute arbitrary code, potentially resulting in a denial of service event. This vulnerability is associated with a buffer overflow in memory, which could allow an attacker to execute arbitrary code or cause a denial of service.
Recommendations For Dell iDRAC Service Module versions 5.3.0.0 and prior, update to a version later than 5.3.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the service module to minimize the risk of exploitation.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-06264
CVE-2024-38490

Affected Products

Dell Idrac Service Module