Lucene search

K
cveDellCVE-2018-1212
HistoryJul 02, 2018 - 5:29 p.m.

CVE-2018-1212

2018-07-0217:29:00
CWE-77
dell
web.nvd.nist.gov
48
dell emc
idrac6
web-based diagnostics
command injection
vulnerability
nvd
cve-2018-1212

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

42.7%

The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected iDRAC system.

Affected configurations

Nvd
Vulners
Node
dellidrac6_modular
OR
dellidrac6_monolithicRange<2.91
VendorProductVersionCPE
dellidrac6_modular*cpe:2.3:a:dell:idrac6_modular:*:*:*:*:*:*:*:*
dellidrac6_monolithic*cpe:2.3:a:dell:idrac6_monolithic:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "iDRAC6 (Monolithic)",
    "vendor": "Dell EMC",
    "versions": [
      {
        "lessThan": "2.91",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "iDRAC6 (Modular)",
    "vendor": "Dell EMC",
    "versions": [
      {
        "lessThanOrEqual": "3.85",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

42.7%

Related for CVE-2018-1212