First published: Fri Mar 23 2018(Updated: )
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell iDRAC7 Firmware | <2.52.52.52 | |
Dell iDRAC8 | <2.52.52.52 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1207 has a high severity level due to the potential for remote code execution by an unauthenticated attacker.
To fix CVE-2018-1207, upgrade the Dell EMC iDRAC7 or iDRAC8 firmware to version 2.52.52.52 or later.
CVE-2018-1207 affects Dell EMC iDRAC7 and iDRAC8 versions prior to 2.52.52.52.
CVE-2018-1207 is classified as a CGI injection vulnerability that allows remote code execution.
Yes, CVE-2018-1207 can be exploited by an unauthenticated remote attacker.