First published: Mon Apr 10 2017(Updated: )
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long SSH username or input.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Integrated Remote Access Controller Firmware | <=2.20.20.20 | |
Dell Integrated Remote Access Controller 7 | ||
Dell Integrated Remote Access Controller 8 | ||
Dell Integrated Remote Access Controller Firmware | <=1.99 | |
Dell Integrated Remote Access Controller 6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7272 is classified as a denial of service vulnerability affecting Dell's iDRAC.
CVE-2015-7272 allows attackers to exploit a buffer overflow via a long SSH username, leading to potential denial of service.
CVE-2015-7272 affects Dell Integrated Remote Access Controller 6 before version 2.80 and 7/8 before version 2.21.21.21.
To mitigate CVE-2015-7272, it is recommended to upgrade to the latest firmware versions of iDRAC.
Specific exploits for CVE-2015-7272 have not been publicly disclosed, but its nature suggests it can be exploited for denial of service.