CVE-2015-7271: Critical severity dell integrated remote access controller firmware vulnerability
Published Apr 10, 2017
·Updated
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo.
Affected Software
3 affected components
Dell Integrated Remote Access Controller Firmware<=2.20.20.20
Dell Integrated Remote Access Controller 7
Dell Integrated Remote Access Controller 8
Event History
Apr 10, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-7271?
CVE-2015-7271 is classified as a high severity vulnerability that can lead to information disclosure.
2
How do I fix CVE-2015-7271?
To fix CVE-2015-7271, update the Dell Integrated Remote Access Controller (iDRAC) firmware to version 2.21.21.21 or later.
3
What features are affected by CVE-2015-7271?
CVE-2015-7271 affects the racadm getsystinfo functionality within the Dell iDRAC 7 and 8 firmware.
4
Can CVE-2015-7271 lead to remote code execution?
CVE-2015-7271 does not directly lead to remote code execution but can expose sensitive information.
5
Who is impacted by CVE-2015-7271?
Users of Dell Integrated Remote Access Controllers (iDRAC) versions prior to 2.21.21.21 are impacted by CVE-2015-7271.