DSA-2022-068: Dell iDRAC9 Security Update for an Improper Authentication Vulnerability
Résumé: Dell EMC iDRAC9 remediation is available for an Improper Authentication vulnerability that may be exploited by malicious users to compromise the affected system.
Cet article concerne
Cet article ne concerne pas
Cet article n’est associé à aucun produit spécifique.
Toutes les versions du produit ne sont pas identifiées dans cet article.
Impact
Critical
Détails
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-24422 | Dell iDRAC9 versions 5.00.00.00 and later but before 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console. | 9.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-24422 | Dell iDRAC9 versions 5.00.00.00 and later but before 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console. | 9.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Produits concernés et mesure corrective
| Product | Affected Versions | Updated Versions | Link to Update |
| Dell iDRAC9 | Versions 5.00.00.00 and later but before 5.10.10.00 | 5.10.10.00 | https://www.dell.com/support/home/drivers/driversdetails?driverid=fptf1 |
| Product | Affected Versions | Updated Versions | Link to Update |
| Dell iDRAC9 | Versions 5.00.00.00 and later but before 5.10.10.00 | 5.10.10.00 | https://www.dell.com/support/home/drivers/driversdetails?driverid=fptf1 |
Historique des révisions
| Revision | Date | Description |
| 1.0 | 2022-05-11 | Initial Release |
Remerciements
Dell would like to thank Christian Mock from CoreTEC for reporting this issue.
Informations connexes
Mention légale
Produits concernés
iDRAC9, iDRAC9 - 5.xx Series, Product Security InformationPropriétés de l’article
Numéro d’article: 000199267
Type d’article: Dell Security Advisory
Dernière modification: 11 May 2022
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.