CVE-2015-7273: XEE
Published Apr 10, 2017
·Updated
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.
Affected Software
3 affected components
Dell Integrated Remote Access Controller Firmware<=2.20.20.20
Dell Integrated Remote Access Controller 7
Dell Integrated Remote Access Controller 8
Event History
Apr 10, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-7273?
CVE-2015-7273 has a medium severity level due to the potential for XML External Entity (XXE) attacks.
2
How do I fix CVE-2015-7273?
To fix CVE-2015-7273, upgrade the Dell Integrated Remote Access Controller firmware to version 2.21.21.21 or higher.
3
What is the impact of CVE-2015-7273 on my system?
The impact of CVE-2015-7273 includes the risk of unauthorized access to sensitive data through XML External Entity (XXE) vulnerabilities.
4
Which versions of iDRAC are affected by CVE-2015-7273?
CVE-2015-7273 affects Dell Integrated Remote Access Controller firmware versions up to 2.20.20.20.
5
Is there a workaround for CVE-2015-7273 if I cannot upgrade?
There is no official workaround for CVE-2015-7273; upgrading the firmware is the recommended solution.