DSA-2019-137: iDRAC Improper Authorization Vulnerability

요약: Dell EMC Servers require a security update to address vulnerabilities in iDRAC Improper Authorization Vulnerability. For specific information on affected platforms and next steps to apply the updates, please refer to this guide. ...

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

Medium

세부 정보

  • Improper Authorization Vulnerability


Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability.  A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as password hashes.

  • Improper Authorization Vulnerability


Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability.  A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as password hashes.

Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

Affected products:
  • Dell EMC iDRAC7 versions prior to 2.65.65.65
  • Dell EMC iDRAC8 versions prior to 2.70.70.70
  • Dell EMC iDRAC9 versions prior to 3.36.36.36
Resolution:      
The following Dell EMC iDRAC firmware releases contain resolutions to these vulnerabilities:
 
iDRAC iDRAC firmware version
iDRAC9 3.36.36.36
3.40.40.40
iDRAC8  2.70.70.70
iDRAC7  2.65.65.65

Note: iDRAC9 and iDRAC8 firmware is available as of the publication date. iDRAC7 firmware is planned to be available April 2020.

Dell EMC recommends all customers upgrade at the earliest opportunity.  

Dell EMC Best Practices regarding iDRAC:
In addition to maintaining up-to-date iDRAC firmware, Dell EMC also advises the following:
  • iDRACs are not designed nor intended to be placed on or connected to the internet; they are intended to be on a separate management network. Placing or connecting iDRACs directly to the internet could expose the connected system to security and other risks for which Dell EMC is not responsible.   
  • Along with locating iDRACs on a separate management subnet, users should isolate the management subnet/VLAN with technologies such as firewalls, and limit access to the subnet/VLAN to authorized server administrators.
  • Dell EMC recommends that customers take into account any deployment factors that may be relevant to their environment to assess their overall risk.
Customers can download software from the Dell Support site:
 https://www.dell.com/support/home/products/server_int/server_int_poweredge
Affected products:
  • Dell EMC iDRAC7 versions prior to 2.65.65.65
  • Dell EMC iDRAC8 versions prior to 2.70.70.70
  • Dell EMC iDRAC9 versions prior to 3.36.36.36
Resolution:      
The following Dell EMC iDRAC firmware releases contain resolutions to these vulnerabilities:
 
iDRAC iDRAC firmware version
iDRAC9 3.36.36.36
3.40.40.40
iDRAC8  2.70.70.70
iDRAC7  2.65.65.65

Note: iDRAC9 and iDRAC8 firmware is available as of the publication date. iDRAC7 firmware is planned to be available April 2020.

Dell EMC recommends all customers upgrade at the earliest opportunity.  

Dell EMC Best Practices regarding iDRAC:
In addition to maintaining up-to-date iDRAC firmware, Dell EMC also advises the following:
  • iDRACs are not designed nor intended to be placed on or connected to the internet; they are intended to be on a separate management network. Placing or connecting iDRACs directly to the internet could expose the connected system to security and other risks for which Dell EMC is not responsible.   
  • Along with locating iDRACs on a separate management subnet, users should isolate the management subnet/VLAN with technologies such as firewalls, and limit access to the subnet/VLAN to authorized server administrators.
  • Dell EMC recommends that customers take into account any deployment factors that may be relevant to their environment to assess their overall risk.
Customers can download software from the Dell Support site:
 https://www.dell.com/support/home/products/server_int/server_int_poweredge

감사의 말

CVE-2019-3764: Dell EMC would like to thank the MilCert Austrian Armed Forces for reporting this issue to us.

관련 정보

해당 제품

iDRAC7, iDRAC8, iDRAC9, iDRAC7 with Lifecycle Controller Version 2.22.22.22, iDRAC7 with Lifecycle Controller Version 2.13.13.12, iDRAC7 with Lifecycle Controller Version 2.15.10.10, iDRAC7 with Lifecycle Controller Version 2.43.43.43 , iDRAC7 with Lifecycle Controller Version 2.21.21.21, iDRAC7 with Lifecycle Controller Version 2.30.30.30, iDRAC7 with Lifecycle Controller Version 2.40.40.40, iDRAC7 with Lifecycle Controller Version 2.41.40.40, iDRAC7/8 with Lifecycle Controller Version 2.50.50.50, iDRAC7/8 with Lifecycle Controller Version 2.52.52.52, iDRAC7/8 with Lifecycle Controller Version 2.60.60.60, iDRAC7/8 with Lifecycle Controller Version 2.61.60.60, iDRAC7/8 with Lifecycle Controller Version 2.62.60.60, iDRAC7/8 with Lifecycle Controller Version 2.63.60.61, iDRAC7/8 with Lifecycle Controller Version 2.63.60.62, iDRAC7 with Lifecycle Controller Version 2.10.10.10, iDRAC7 with Lifecycle Controller Version 2.20.20.20, iDRAC7 with Lifecycle Controller Version 2.31.31.30, iDRAC7 with Lifecycle Controller Version 2.32.31.30, iDRAC7 Version 1.65.65, iDRAC7 Version 1.66.65, iDRAC8 with Lifecycle Controller Version 2.12.12.12, iDRAC8 with Lifecycle Controller Version 2.14.14.12, iDRAC8 with Lifecycle Controller Version 2.17.17.13, iDRAC8 with Lifecycle Controller Version 2.18.17.13, iDRAC8 with Lifecycle Controller Version 2.30.119.30, iDRAC8 with Lifecycle Controller Version 2.35.35.35, iDRAC8 with Lifecycle Controller Version 2.42.110.40, iDRAC8 with Lifecycle Controller Version 2.45.45.40, iDRAC8 with Lifecycle Controller Version 2.55.55.50, iDRAC8 with Lifecycle Controller Version 2.04.02.01, iDRAC8 with Lifecycle Controller Version 2.05.05.05, iDRAC8 with Lifecycle Controller Version 2.23.23.21, iDRAC9 - 3.0x Series, iDRAC9 - 3.1x Series, iDRAC9 - 3.2x Series, iDRAC9 - 3.3x Series, iDRAC7 Version 1.00.00, iDRAC7 Version 1.10.10, iDRAC7 Version 1.20.20, iDRAC7 Version 1.30.30, iDRAC7 Version 1.35.35, iDRAC7 Version 1.40.40, iDRAC7 Version 1.50.50, iDRAC7 Version 1.51.51, iDRAC7 Version 1.55.55, iDRAC7 Version 1.56.55, iDRAC7 Version 1.57.57, iDRAC8 with Lifecycle Controller Version 2.00.00.00, iDRAC8 with Lifecycle Controller Version 2.02.01.01, Product Security Information ...
문서 속성
문서 번호: 000177303
문서 유형: Dell Security Advisory
마지막 수정 시간: 06 5월 2026
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.