CVE-2021-36348

HIGH

iDRAC9 <5.00.20.00 - Command Injection

Title source: llm
STIX 2.1

Description

iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.dell.com/support/kbdoc/000194038

Scores

CVSS v3 8.1
EPSS 0.0055
EPSS Percentile 68.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
dell/integrated_dell_remote_access_controller_9_firmware < 5.00.20.00
Published Jan 25, 2022
Tracked Since Feb 18, 2026