CRITICAL
Web Interface Authentication Bypass Vulnerability
Published Apr 26, 2019
9.8
CRITICALCVSS 3.0
EPSS 3.31%
Description
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface.
Affected products
-
- Version 3.21.25.22StatusaffectedConstraints<3.21.25.22
- Version 3.21.26.22StatusaffectedConstraints<3.21.26.22
- Version 3.22.22.22StatusaffectedConstraints<3.22.22.22
- Version 3.24.24.24StatusaffectedConstraints<3.24.24.24
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
OR
- 3.20.21.20
- 3.21.24.22
- 3.23.23.23
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (1)
- https://www.dell.com/support/article/us/en/04/sln316930/dsa-2019-028-dell-emc-idrac-multiple-vulnerabilities?lang=en x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.dell.com/support/article/us/en/04/sln316930/dsa-2019-028-dell-emc-idrac-multiple-vulnerabilities?lang=en | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published Apr 26, 2019
Updated Sep 17, 2024
Reserved Jan 3, 2019
Link CVE-2019-3706
CISA Vulnrichment
Updated n/a