35770exploit
http://www.exploit-db.com/exploits/35770 CVE-2014-8272
Dell iDRAC IPMI 1.5 - Insufficient Session ID Randomness
Record summary
CVE-2014-8272 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBDell iDRAC IPMI 1.5 - Insufficient Session ID RandomnessExploitDB exploitby Yong Chuan_ KohNot analyzed1 file
Repository PoCs
GitLabyongchuank/cve-2014-8272-dell-idrac-ipmi-weak-sessionidRepository PoCby yongchuankStars: 0Not analyzed4 files
References
4VU#843044Third-party advisory
http://www.kb.cert.org/vuls/id/843044 kb.cert.orgConfirmation
http://www.kb.cert.org/vuls/id/BLUU-9RDQHM nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-8272