Lucene search

K
cveDellCVE-2019-3705
HistoryApr 26, 2019 - 7:29 p.m.

CVE-2019-3705

2019-04-2619:29:00
CWE-787
CWE-120
dell
web.nvd.nist.gov
51
dell emc
idrac
cve-2019-3705
vulnerability
buffer overflow
security issue
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.01

Percentile

83.4%

Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or execute arbitrary code on the system with privileges of the webserver by sending specially crafted input data to the affected system.

Affected configurations

Nvd
Vulners
Node
dellidrac6_firmwareRange<2.92
OR
dellidrac7_firmwareRange<2.61.60.60
OR
dellidrac8_firmwareRange<2.61.60.60
OR
dellidrac9_firmwareRange<3.20.21.20
VendorProductVersionCPE
dellidrac6_firmware*cpe:2.3:o:dell:idrac6_firmware:*:*:*:*:*:*:*:*
dellidrac7_firmware*cpe:2.3:o:dell:idrac7_firmware:*:*:*:*:*:*:*:*
dellidrac8_firmware*cpe:2.3:o:dell:idrac8_firmware:*:*:*:*:*:*:*:*
dellidrac9_firmware*cpe:2.3:o:dell:idrac9_firmware:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "iDRAC",
    "vendor": "Dell EMC",
    "versions": [
      {
        "lessThan": "2.92",
        "status": "affected",
        "version": "2.92",
        "versionType": "custom"
      },
      {
        "lessThan": "2.61.60.60",
        "status": "affected",
        "version": "2.61.60.60",
        "versionType": "custom"
      },
      {
        "lessThan": "3.20.21.20",
        "status": "affected",
        "version": "3.20.21.20",
        "versionType": "custom"
      },
      {
        "lessThan": "3.21.24.22",
        "status": "affected",
        "version": "3.21.24.22",
        "versionType": "custom"
      },
      {
        "lessThan": "3.23.23.23",
        "status": "affected",
        "version": "3.23.23.23",
        "versionType": "custom"
      },
      {
        "lessThan": "3.21.26.22",
        "status": "affected",
        "version": "3.21.26.22",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.01

Percentile

83.4%

Related for CVE-2019-3705