Unsolved

752

September 21st, 2020 11:00

iDRAC8 - 2.70.70.70 - CVE-2020-5344

Team,

There is a vulnerability seen at customer side for the iDRAC8 (R630s) - https://www.dell.com/support/article/en-uk/sln320717/dsa-2020-063-idrac-buffer-overflow-vulnerability?lang=en. This KB article was published on March 25th, 2020. It says fix is at version 2.70.70.70. However, we upgraded the same iDRAC version for R630s back in Jan 2020.

I looked at the https://www.dell.com/support/home/en-uk/drivers/driversdetails?driverid=dnh17 download page, it says page was updated on 25th Mar, 2020, but don’t see an update on the version name (Version 2.70.70.70, A00).

Could you please check and suggest if this vulnerability is already covered in the iDRAC version which was released back in Oct, 2019, or is there an new update in the same iDRAC version from Dell which has the fix.

Best regards,

Chethan

6 Operator

 • 

2.9K Posts

September 21st, 2020 15:00

There wouldn't be a new 2.70.70.70 release to apply, however, I would recommend updating to 2.75.75.75. This would address concerns you have with this CVE, in addition to another relating to NTP. 

 

iDRAC 2.75.75.75:https://dell.to/33RSqP7

CVE Description: https://dell.to/35R7iQi

No Events found!

Top