CVE-2018-1207: Code Injection
Published Mar 23, 2018
·Updated
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.
Affected Software
2 affected components
Dell EMC iDRAC7<2.52.52.52
Dell Emc Idrac8<2.52.52.52
Event History
Mar 23, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Apr 16, 2025
Exploit Published
12:00 AM
Known Exploited
09:51 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-1207?
CVE-2018-1207 has a high severity level due to the potential for remote code execution by an unauthenticated attacker.
2
How do I fix CVE-2018-1207?
To fix CVE-2018-1207, upgrade the Dell EMC iDRAC7 or iDRAC8 firmware to version 2.52.52.52 or later.
3
Which versions of Dell EMC iDRAC are affected by CVE-2018-1207?
CVE-2018-1207 affects Dell EMC iDRAC7 and iDRAC8 versions prior to 2.52.52.52.
4
What type of vulnerability is CVE-2018-1207?
CVE-2018-1207 is classified as a CGI injection vulnerability that allows remote code execution.
5
Can CVE-2018-1207 be exploited without authentication?
Yes, CVE-2018-1207 can be exploited by an unauthenticated remote attacker.