First published: Tue Jun 26 2018(Updated: )
Dell EMC iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for certain URLs. A man-in-the-middle attacker could use this vulnerability to strip the SSL/TLS protection from a connection between a client and a server.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Idrac9 Firmware | <3.21.21.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1249 is a vulnerability in Dell EMC iDRAC9 versions prior to 3.21.21.21 that allows a man-in-the-middle attacker to strip the SSL/TLS protection from a connection between a client and a server.
CVE-2018-1249 allows a man-in-the-middle attacker to strip the SSL/TLS protection from a connection to iDRAC web server for certain URLs.
CVE-2018-1249 has a severity rating of medium with a CVSS score of 5.9.
To fix CVE-2018-1249, update Dell EMC iDRAC9 firmware to version 3.21.21.21 or above.
You can find more information about CVE-2018-1249 on the Dell Community website: http://en.community.dell.com/techcenter/extras/m/white_papers/20487494