CVE-2013-4783: Critical severity dell idrac6 firmware vulnerability
The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password. NOTE: the vendor disputes the significance of this issue, stating "DRAC's are intended to be on a separate management network; they are not designed nor intended to be placed on or connected to the Internet."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4783?
CVE-2013-4783 is rated as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2013-4783?
To mitigate CVE-2013-4783, update the firmware of the affected Dell iDRAC6 or iDRAC7 to their latest versions.
Who is affected by CVE-2013-4783?
CVE-2013-4783 affects users of Dell iDRAC6 with firmware versions before 1.92 and iDRAC7 with firmware versions before 1.23.23.
What type of attacks can exploit CVE-2013-4783?
CVE-2013-4783 allows remote attackers to bypass authentication and execute arbitrary IPMI commands, leading to unauthorized access.
What is the main cause of CVE-2013-4783?
The main cause of CVE-2013-4783 is the use of cipher suite 0 (cipher zero) and an arbitrary password, which facilitates the authentication bypass.