DSA-2020-063: iDRAC Buffer Overflow Vulnerability

DSA-2020-063: iDRAC Buffer Overflow Vulnerability


DSA ID: DSA-2020-063
CVE Identifier: CVE-2020-5344
Severity: High

Severity Rating: CVSSv3 Base Score: 7.0 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H)

Affected products:
  • Dell EMC iDRAC7 versions prior to 2.65.65.65
  • Dell EMC iDRAC8 versions prior to 2.70.70.70
  • Dell EMC iDRAC9 versions prior to 4.00.00.00
Summary:
Dell EMC iDRAC has been updated to address a vulnerability that may be exploited to compromise the affected systems.

Details:
  • Buffer Overflow Vulnerability
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.

Resolution:
The following Dell EMC iDRAC firmware releases contain resolutions to these vulnerabilities:

iDRAC

iDRAC firmware version

iDRAC9

4.00.00.00

iDRAC8

2.70.70.70

iDRAC7

2.65.65.65


Note: Available as of the publication date.

Dell EMC recommends all customers upgrade at the earliest opportunity.

Dell EMC Best Practices regarding iDRAC:
  • The iDRAC is intended to be on a separate management network. The iDRAC is not designed nor intended to be placed on, nor connected directly to the Internet. Doing so could expose the connected system to security and other risks for which Dell EMC is not responsible.
  • Dell EMC recommends using the Dedicated Gigabit Ethernet port available on rack and tower servers to connect the iDRAC to a separate management network.
  • Along with locating iDRAC on a separate management network, users should isolate the management subnet/vLAN with technologies such as firewalls, and limit access to the subnet/vLAN to authorized server administrators.
  • Dell EMC recommends using 256-bit encryption strength as well as TLS 1.2 or higher. For tighter control, additional ciphers may be removed via "Cipher Select" – see the iDRAC User Guide for more details.
  • Dell EMC recommends additional settings such as IP range filtering and System Lockdown Mode.
  • Dell EMC recommends using additional security authentication options such as Microsoft Active Directory or LDAP.
  • Dell EMC recommends keeping iDRAC firmware up to date.
Link to remedies:

Customers can download software, including the latest release of iDRAC firmware, from the Dell Support site. https://www.dell.com/support/home/

Customers can find the iDRAC documentation from the Dell EMC Support site. www.dell.com/idracmanuals


Dell EMC recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. Dell EMC disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall Dell EMC, or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Dell EMC or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.





Quick Tips content is self-published by the Dell Support Professionals who resolve issues daily. In order to achieve a speedy publication, Quick Tips may represent only partial solutions or work-arounds that are still in development or pending further proof of successfully resolving an issue. As such Quick Tips have not been reviewed, validated or approved by Dell and should be used with appropriate caution. Dell shall not be liable for any loss, including but not limited to loss of data, loss of profit or loss of revenue, which customers may incur by following any procedure or advice set out in the Quick Tips.

Article ID: SLN320717

Last Date Modified: 03/30/2020 03:48 PM


Rate this article

Accurate
Useful
Easy to understand
Was this article helpful?
Yes No
Send us feedback
Comments cannot contain these special characters: <>()\
Sorry, our feedback system is currently down. Please try again later.

Thank you for your feedback.