Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products

DSA-2021-041: Dell iDRAC 8 Security Update for a host header injection vulnerability.

Summary: DSA-2021-041: Dell iDRAC 8 Security Update for a host header injection vulnerability.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

 
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21510 Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability.  A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.   6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
 
 
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21510 Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability.  A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.   6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
 
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

 
Product Affected Version(s) Updated Version(s) CVE Link to Update
iDRAC8 Versions prior to 2.75.100.75 Dell iDRAC8 2.75.100.75 CVE-2021-21510 Customers can download software, including the latest release of iDRAC firmware, from the Dell Support site at https://www.dell.com/support/home/

Customers can find the iDRAC documentation from the Dell EMC Support site at www.dell.com/idracmanuals
 
 

 
Product Affected Version(s) Updated Version(s) CVE Link to Update
iDRAC8 Versions prior to 2.75.100.75 Dell iDRAC8 2.75.100.75 CVE-2021-21510 Customers can download software, including the latest release of iDRAC firmware, from the Dell Support site at https://www.dell.com/support/home/

Customers can find the iDRAC documentation from the Dell EMC Support site at www.dell.com/idracmanuals
 
 

Revision History

 

RevisionDateDescription
1.02021-03-04Initial Release

Acknowledgements

CVE-2021-21510: Dell would like to thank Ken Pyle from CYBIR for reporting this vulnerability.

Related Information

Affected Products

iDRAC8, iDRAC8 with Lifecycle Controller Version 2.12.12.12, iDRAC8 with Lifecycle Controller Version 2.14.14.12, iDRAC8 with Lifecycle Controller Version 2.17.17.13, iDRAC8 with Lifecycle Controller Version 2.18.17.13 , iDRAC8 with Lifecycle Controller Version 2.30.119.30, iDRAC8 with Lifecycle Controller Version 2.35.35.35, iDRAC8 with Lifecycle Controller Version 2.42.110.40, iDRAC8 with Lifecycle Controller Version 2.45.45.40, iDRAC8 with Lifecycle Controller Version 2.55.55.50, iDRAC8 with Lifecycle Controller version 2.70.70.70, iDRAC8 with Lifecycle Controller version 2.75.75.75, iDRAC8 with Lifecycle Controller Version 2.04.02.01, iDRAC8 with Lifecycle Controller Version 2.05.05.05, iDRAC8 with Lifecycle Controller Version 2.23.23.21, iDRAC8 with Lifecycle Controller Version 2.00.00.00, iDRAC8 with Lifecycle Controller Version 2.02.01.01, Product Security Information ...
Article Properties
Article Number: 000183758
Article Type: Dell Security Advisory
Last Modified: 23 Nov 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.