CVE-2016-5685: Critical severity dell emc idrac7 vulnerability
Published Nov 29, 2016
·Updated
Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.
Affected Software
4 affected components
Dell Idrac7 Firmware<=2.30.30.30
Dell Idrac8 Firmware<=2.30.30.30
Dell iDRAC7
Dell iDRAC8
Event History
Nov 29, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-5685?
CVE-2016-5685 has a medium severity rating due to the potential for authenticated users to access sensitive system functions.
2
How do I fix CVE-2016-5685?
To fix CVE-2016-5685, upgrade the firmware of Dell iDRAC7 and iDRAC8 devices to version 2.40.40.40 or later.
3
Who is affected by CVE-2016-5685?
CVE-2016-5685 affects authenticated users of Dell iDRAC7 and iDRAC8 devices with firmware versions up to 2.30.30.30.
4
What type of access does CVE-2016-5685 allow?
CVE-2016-5685 allows authenticated users to gain Bash shell access, enabling potential unauthorized actions on the device.
5
When was CVE-2016-5685 disclosed?
CVE-2016-5685 was disclosed in 2016 and impacts multiple versions of Dell iDRAC firmware.