Lucene search

K
cvelistDellCVELIST:CVE-2019-3705
HistoryApr 26, 2019 - 6:22 p.m.

CVE-2019-3705 Buffer Overflow Vulnerability

2019-04-2618:22:08
CWE-120
dell
www.cve.org
5

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.01

Percentile

83.4%

Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or execute arbitrary code on the system with privileges of the webserver by sending specially crafted input data to the affected system.

CNA Affected

[
  {
    "product": "iDRAC",
    "vendor": "Dell EMC",
    "versions": [
      {
        "lessThan": "2.92",
        "status": "affected",
        "version": "2.92",
        "versionType": "custom"
      },
      {
        "lessThan": "2.61.60.60",
        "status": "affected",
        "version": "2.61.60.60",
        "versionType": "custom"
      },
      {
        "lessThan": "3.20.21.20",
        "status": "affected",
        "version": "3.20.21.20",
        "versionType": "custom"
      },
      {
        "lessThan": "3.21.24.22",
        "status": "affected",
        "version": "3.21.24.22",
        "versionType": "custom"
      },
      {
        "lessThan": "3.23.23.23",
        "status": "affected",
        "version": "3.23.23.23",
        "versionType": "custom"
      },
      {
        "lessThan": "3.21.26.22",
        "status": "affected",
        "version": "3.21.26.22",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.01

Percentile

83.4%

Related for CVELIST:CVE-2019-3705