We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2018-1212

Authenticated remote code execution in iDRAC 6



Assignerdell
Reserved2017-12-06
Published2018-07-02
Updated2024-09-17

Description

The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected iDRAC system.



HIGH: 8.8CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Product status

Any version before 2.91
affected

Any version
affected

Credits

Dell EMC would like to thank Arseniy for reporting this issue to us.

References

http://en.community.dell.com/techcenter/extras/m/white_papers/20487494

cve.org CVE-2018-1212

nvd.nist.gov CVE-2018-1212

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2018-1212
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.