First published: Mon Jul 08 2013(Updated: )
The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password. NOTE: the vendor disputes the significance of this issue, stating "DRAC's are intended to be on a separate management network; they are not designed nor intended to be placed on or connected to the Internet."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dell iDRAC6 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4783 is rated as a high severity vulnerability due to its potential for remote exploitation.
To mitigate CVE-2013-4783, update the firmware of the affected Dell iDRAC6 or iDRAC7 to their latest versions.
CVE-2013-4783 affects users of Dell iDRAC6 with firmware versions before 1.92 and iDRAC7 with firmware versions before 1.23.23.
CVE-2013-4783 allows remote attackers to bypass authentication and execute arbitrary IPMI commands, leading to unauthorized access.
The main cause of CVE-2013-4783 is the use of cipher suite 0 (cipher zero) and an arbitrary password, which facilitates the authentication bypass.