CVE-2018-1249: iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for certain URLs
Dell EMC iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for certain URLs. A man-in-the-middle attacker could use this vulnerability to strip the SSL/TLS protection from a connection between a client and a server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1249?
CVE-2018-1249 is a vulnerability in Dell EMC iDRAC9 versions prior to 3.21.21.21 that allows a man-in-the-middle attacker to strip the SSL/TLS protection from a connection between a client and a server.
How does CVE-2018-1249 impact Dell EMC iDRAC9?
CVE-2018-1249 allows a man-in-the-middle attacker to strip the SSL/TLS protection from a connection to iDRAC web server for certain URLs.
What is the severity of CVE-2018-1249?
CVE-2018-1249 has a severity rating of medium with a CVSS score of 5.9.
How can I fix CVE-2018-1249?
To fix CVE-2018-1249, update Dell EMC iDRAC9 firmware to version 3.21.21.21 or above.
Where can I find more information about CVE-2018-1249?
You can find more information about CVE-2018-1249 on the Dell Community website: http://en.community.dell.com/techcenter/extras/m/white_papers/20487494