DSA-2024-018: Security Update for Dell iDRAC Service Module for Weak Folder Permission Vulnerabilities
Summary:
Dell iDRAC Service Module remediation is available for iSM for Windows versions 5.3.0.0, 5.2.0.0 and 5.1.0.0 , which could be exploited by malicious users to compromise the affected
system.
...
Please select a product to check article relevancy
This article applies to This article does not apply toThis article is not tied to any specific product.Not all product versions are identified in this article.
This remediation is only applicable if Dell iDRAC Service Module (iSM) for Windows is installed in a custom location other than C:\Program Files\Dell\SysMgt.
Details
Proprietary Code CVEs
Description
CVSS Base Score
CVSS Vector String
CVE-2024-22428
Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity.
Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
NOTE: In addition to the below wording pointing specifically at a Windows-based tree structure. Dell confirms the issue discussed in this Security Advisory:
- does not impact the Linux version of the iDRAC Service Module,
- does not impact the iDRAC Service Module ViB for ESXi.
The hotfix is only applicable to hosts running Microsoft Windows Server and Client operating systems.
This patch is only applicable if Dell iDRAC Service Module (iSM) is installed in a custom location other than the default path: “C:\Program Files\Dell\SysMgt\”
Workarounds & Mitigations
CVE ID
Workaround and Mitigation
CVE-2024-22428
Install iSM at the default location
Revision History
Revision
Date
Description
1.0
2024-01-15
Initial Release.
2.0
2024-01-16
Changes to formatting without content changes.
3.0
2024-01-18
Updated the "Affected Versions" to read 5.2.0.0.
4.0
2024-01-30
Updated the additional info field to highlight this only applies to specific OSes.
5.0
2024-02-07
added specific links to hotfix and full download for Windows.
6.0
2024-02-12
minor formatting changes and URL link spelling update.
7.0
2024-02-13
formating update without content changes.
8.0
2024-02-16
Added specific language targeted at Linux-based and ESXi versions of iSM