First published: Fri Dec 19 2014(Updated: )
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dell iDRAC6 modular | <=3.60 | |
Dell iDRAC7 | <=1.56.55 | |
Intel Ipmi | =1.5 | |
Dell iDRAC6 monolithic | <=1.97 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.