DSA-2021-082: Dell iDRAC 9 Security Update for Improper Authentication Vulnerability

Samenvatting: Dell iDRAC 9 contains remediation for an improper authentication vulnerability that may be exploited by malicious users to compromise the affected system.

Dit artikel is van toepassing op Dit artikel is niet van toepassing op Dit artikel is niet gebonden aan een specifiek product. Niet alle productversies worden in dit artikel vermeld.

Impact

Critical

Gegevens

Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21538 Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the virtual console. 9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21538 Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the virtual console. 9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Dell Technologies raadt aan dat alle klanten rekening houden met zowel de basisscore van CVSS als alle relevante tijdelijke en omgevingsscores die gevolgen kunnen hebben voor de mogelijke ernst van de specifieke beveiligingsproblemen.

Getroffen producten en herstel

Product Affected Version(s) Updated Version(s) Link to Update
iDRAC9 Versions 4.40.00.00 and later, but prior to 4.40.10.00 4.40.10.00 Customers can download software, including the latest release of iDRAC firmware, from the Dell Support site at https://www.dell.com/support/home/

Customers can find the iDRAC documentation from the Dell EMC Support site at www.dell.com/idracmanuals
 
Product Affected Version(s) Updated Version(s) Link to Update
iDRAC9 Versions 4.40.00.00 and later, but prior to 4.40.10.00 4.40.10.00 Customers can download software, including the latest release of iDRAC firmware, from the Dell Support site at https://www.dell.com/support/home/

Customers can find the iDRAC documentation from the Dell EMC Support site at www.dell.com/idracmanuals
 

Revisiegeschiedenis

RevisionDateDescription
1.02021-05-10Initial Release

Verwante informatie

Getroffen producten

iDRAC9, iDRAC9 - 4.xx Series, Product Security Information
Artikeleigenschappen
Artikelnummer: 000186420
Artikeltype: Dell Security Advisory
Laatst aangepast: 10 mei 2021
Vind antwoorden op uw vragen via andere Dell gebruikers
Support Services
Controleer of uw apparaat wordt gedekt door Support Services.