Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000199284


DSA-2022-094: Dell Precision Workstation 7920 Rack Security Update for iDRAC Vulnerability

Summary: Dell Client remediation is available for an Improper Authentication vulnerability that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

Critical

Details

Proprietary Code CVE  Description CVSS Base Score CVSS Vector String
CVE-2022-24422 Dell iDRAC9 versions 5.00.00.00 and later but before version 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console. 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Proprietary Code CVE  Description CVSS Base Score CVSS Vector String
CVE-2022-24422 Dell iDRAC9 versions 5.00.00.00 and later but before version 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console. 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Affected Versions Updated Versions Link to Update
Precision 7920 Rack iDRAC9: Versions 5.00.00.00 and later but before 5.10.10.00 5.10.10.00 https://www.dell.com/support/home/drivers/driversdetails?driverid=fptf1
Product Affected Versions Updated Versions Link to Update
Precision 7920 Rack iDRAC9: Versions 5.00.00.00 and later but before 5.10.10.00 5.10.10.00 https://www.dell.com/support/home/drivers/driversdetails?driverid=fptf1
Revision History

RevisionDateDescription
1.02022/06/06Initial Release

Related Information

Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide


Article Properties


Affected Product

Precision 7920 Rack

Last Published Date

07 Jun 2022

Version

4

Article Type

Dell Security Advisory