Assigner | dell |
Reserved | 2024-02-13 |
Published | 2024-06-29 |
Updated | 2024-07-02 |
Description
iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker could potentially exploit this vulnerability, leading to arbitrary code execution on the vulnerable application.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L |
Problem types
CWE-330: Use of Insufficiently Random Values
Product status
Any version before 7.00.00.172
Any version before 7.10.50.00
References
https://www.dell.com/support/kbdoc/en-us/000226503/dsa-2024-099-security-update-for-dell-idrac9-ipmi-session-vulnerability