IDPA: iDRAC UI fails to connect in browser using FQDN after 2.7.2 upgrade

Summary: (CVE-2021-21510) - Dell EMC iDRAC9 versions prior to IDPA 2.7.2 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary 'Host' header values to poison a web-cache or trigger redirections. After IDPA v.2.7.2 upgrade, connection to iDRAC using only Fully Qualified Domain Name (FQDN) will fail to connect. Connecting using IP works as intended. ...

Acest articol se aplică pentru Acest articol nu se aplică pentru Acest articol nu este legat de un produs specific. Acest articol nu acoperă toate versiunile de produs existente.

Symptoms

When accessing the iDRAC UI using FQDN after a v.2.7.2 upgrade, the browser fails with connectivity issues like redirection, '400 - Bad Request' errors or Unknown Reason.

 

Screenshot of Error Message: The server encountered an internal error or misconfiguration and was unable to complete your request

Screenshot of Error Message: An error occurred during a connection to iDRAC

 

Cause

IDPA 2.7.2 block contains iDRAC firmware version 5.10.00.00 which introduced HTTPS connection changes as part of the CVE-2021-21510 fix. The webserver in iDRAC firmware version 5.10.00.00 enforces an HTTPS Host Header check by default.

This also impacts Fully Qualified Domain Name (FQDN) addresses. 

Resolution

DP4400 iDRAC can be accessed by using configured IP as expected. No other changes are required. iDRAC is no longer accessible by FQDN.

See the PowerProtect DP4400 Installation Guide for steps to configure networking, as was meant to be performed at initial deployment.

DP5x00 and DP8x00 are not deployed with external connection by default.

Additional Information

Produse afectate

PowerProtect DP4400, PowerProtect DP5300, PowerProtect DP5800, PowerProtect DP8300, PowerProtect DP8800, Integrated Data Protection Appliance Family, Integrated Data Protection Appliance Software, PowerProtect DP5900, PowerProtect DP8400 , PowerProtect DP8900 ...
Proprietăți articol
Article Number: 000197115
Article Type: Solution
Ultima modificare: 09 dec. 2025
Version:  8
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.