DSA-2019-028: Dell EMC iDRAC Multiple Vulnerabilities

Yhteenveto: Dell EMC iDRAC has been updated to address multiple vulnerabilities which may potentially be exploited to compromise the affected systems.

Tämä artikkeli koskee tuotetta Tämä artikkeli ei koske tuotetta Tämä artikkeli ei liity tiettyyn tuotteeseen. Tässä artikkelissa ei yksilöidä kaikkia tuoteversioita.

Vaikutus

High

Tiedot

  • Buffer Overflow Vulnerability (CVE-2019-3705)
     
Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or execute arbitrary code on the system with privileges of the webserver by sending specially crafted input data to the affected system.
CVSSv3 Base Score 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
 
  • Web Interface Authentication Bypass Vulnerability (CVE-2019-3706)
 
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface.
CVSSv3 Base Score 8.6 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H)
 
  • WS-MAN Authentication Bypass Vulnerability (CVE-2019-3707)
 
Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted input data to the WS-MAN interface.
 
CVSSv3 Base Score 8.6 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H)
  • Buffer Overflow Vulnerability (CVE-2019-3705)
     
Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or execute arbitrary code on the system with privileges of the webserver by sending specially crafted input data to the affected system.
CVSSv3 Base Score 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
 
  • Web Interface Authentication Bypass Vulnerability (CVE-2019-3706)
 
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface.
CVSSv3 Base Score 8.6 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H)
 
  • WS-MAN Authentication Bypass Vulnerability (CVE-2019-3707)
 
Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted input data to the WS-MAN interface.
 
CVSSv3 Base Score 8.6 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H)
Dell Technologies suosittelee, että kaikki asiakkaat ottavat huomioon sekä CVSS-peruspistemäärän että kaikki asiaankuuluvat väliaikaiset ja ympäristöön liittyvät pisteet, jotka voivat vaikuttaa tietyn tietoturvahaavoittuvuuden mahdolliseen vakavuuteen.

Tuotteet, joihin asia vaikuttaa, ja tilanteen korjaaminen


Affected products:
 
  • Dell EMC iDRAC6 versions prior to 2.92 (CVE-2019-3705)
  • Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 (CVE-2019-3705)
  • Dell EMC iDRAC9 versions prior to 3.30.30.30, 3.20.21.20, 3.21.24.22, 3.21.26.22, 3.23.23.23, 3.24.24.24, 3.22.22.22, 3.21.25.22 (CVE-2019-3705, CVE-2019-3706, and CVE-2019-3707)

Remediation:      
The following Dell EMC iDRAC firmware releases contain resolutions to these vulnerabilities:
 
iDRAC iDRAC firmware version
iDRAC9 3.20.21.20
3.21.24.22
3.21.26.22
3.23.23.23
  3.24.24.24
  3.22.22.22
  3.21.25.22
  3.30.30.30
iDRAC8 2.61.60.60
iDRAC7 2.61.60.60
iDRAC6 2.92


Dell EMC recommends all customers upgrade at the earliest opportunity.  

Dell Best Practices regarding iDRAC:

In addition to maintaining up to date iDRAC firmware, Dell also advises the following:
  • iDRACs are not designed nor intended to be placed on or connected to the internet; they are intended to be on a separate management network.  Placing or connecting iDRACs directly to the internet could expose the connected system to security and other risks for which Dell is not responsible.   
  • Along with locating iDRACs on a separate management subnet, users should isolate the management subnet/vLAN with technologies such as firewalls, and limit access to the subnet/vLAN to authorized server administrators.
  • Dell recommends that customers take into account any deployment factors that may be relevant to their environment to assess their overall risk.

Customers can download iDRAC firmware for PowerEdge servers. For all other platforms, please select the platform from the Dell support site.

Affected products:
 
  • Dell EMC iDRAC6 versions prior to 2.92 (CVE-2019-3705)
  • Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 (CVE-2019-3705)
  • Dell EMC iDRAC9 versions prior to 3.30.30.30, 3.20.21.20, 3.21.24.22, 3.21.26.22, 3.23.23.23, 3.24.24.24, 3.22.22.22, 3.21.25.22 (CVE-2019-3705, CVE-2019-3706, and CVE-2019-3707)

Remediation:      
The following Dell EMC iDRAC firmware releases contain resolutions to these vulnerabilities:
 
iDRAC iDRAC firmware version
iDRAC9 3.20.21.20
3.21.24.22
3.21.26.22
3.23.23.23
  3.24.24.24
  3.22.22.22
  3.21.25.22
  3.30.30.30
iDRAC8 2.61.60.60
iDRAC7 2.61.60.60
iDRAC6 2.92


Dell EMC recommends all customers upgrade at the earliest opportunity.  

Dell Best Practices regarding iDRAC:

In addition to maintaining up to date iDRAC firmware, Dell also advises the following:
  • iDRACs are not designed nor intended to be placed on or connected to the internet; they are intended to be on a separate management network.  Placing or connecting iDRACs directly to the internet could expose the connected system to security and other risks for which Dell is not responsible.   
  • Along with locating iDRACs on a separate management subnet, users should isolate the management subnet/vLAN with technologies such as firewalls, and limit access to the subnet/vLAN to authorized server administrators.
  • Dell recommends that customers take into account any deployment factors that may be relevant to their environment to assess their overall risk.

Customers can download iDRAC firmware for PowerEdge servers. For all other platforms, please select the platform from the Dell support site.

Asiaan liittyvät tiedot

Tuotteet, joihin vaikutus kohdistuu

iDRAC6, iDRAC7, iDRAC8, iDRAC9, iDRAC7 with Lifecycle Controller Version 2.22.22.22, iDRAC7 with Lifecycle Controller Version 2.13.13.12, iDRAC7 with Lifecycle Controller Version 2.15.10.10, iDRAC7 with Lifecycle Controller Version 2.43.43.43 , iDRAC7 with Lifecycle Controller Version 2.21.21.21, iDRAC7 with Lifecycle Controller Version 2.30.30.30, iDRAC7 with Lifecycle Controller Version 2.40.40.40, iDRAC7 with Lifecycle Controller Version 2.41.40.40, iDRAC7/8 with Lifecycle Controller Version 2.50.50.50, iDRAC7/8 with Lifecycle Controller Version 2.52.52.52, iDRAC7/8 with Lifecycle Controller Version 2.60.60.60, iDRAC7 with Lifecycle Controller Version 2.10.10.10, iDRAC7 with Lifecycle Controller Version 2.20.20.20, iDRAC7 with Lifecycle Controller Version 2.31.31.30, iDRAC7 with Lifecycle Controller Version 2.32.31.30, iDRAC7 Version 1.65.65, iDRAC7 Version 1.66.65, iDRAC8 with Lifecycle Controller Version 2.12.12.12, iDRAC8 with Lifecycle Controller Version 2.14.14.12, iDRAC8 with Lifecycle Controller Version 2.17.17.13, iDRAC8 with Lifecycle Controller Version 2.18.17.13, iDRAC8 with Lifecycle Controller Version 2.30.119.30, iDRAC8 with Lifecycle Controller Version 2.35.35.35, iDRAC8 with Lifecycle Controller Version 2.42.110.40, iDRAC8 with Lifecycle Controller Version 2.45.45.40, iDRAC8 with Lifecycle Controller Version 2.55.55.50, iDRAC8 with Lifecycle Controller Version 2.04.02.01, iDRAC8 with Lifecycle Controller Version 2.05.05.05, iDRAC8 with Lifecycle Controller Version 2.23.23.21, iDRAC9 - 3.0x Series, iDRAC9 - 3.1x Series, iDRAC9 - 3.2x Series, iDRAC7 Version 1.00.00, iDRAC7 Version 1.10.10, iDRAC7 Version 1.20.20, iDRAC7 Version 1.30.30, iDRAC7 Version 1.35.35, iDRAC7 Version 1.40.40, iDRAC7 Version 1.50.50, iDRAC7 Version 1.51.51, iDRAC7 Version 1.55.55, iDRAC7 Version 1.56.55, iDRAC7 Version 1.57.57, iDRAC8 with Lifecycle Controller Version 2.00.00.00, iDRAC8 with Lifecycle Controller Version 2.02.01.01, Product Security Information ...
Artikkelin ominaisuudet
Artikkelin numero: 000180622
Artikkelin tyyppi: Dell Security Advisory
Viimeksi muutettu: 18 syysk. 2025
Etsi vastauksia kysymyksiisi muilta Dell-käyttäjiltä
Tukipalvelut
Tarkista, kuuluuko laitteesi tukipalveluiden piiriin.