CVE-2018-15774: iDRAC7/iDRAC8/iDRAC9 - Privilege Escalation Vulnerability
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with operator privileges could potentially exploit a permissions check flaw in the Redfish interface to gain administrator access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15774?
CVE-2018-15774 is a privilege escalation vulnerability in Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23.
Who is affected by CVE-2018-15774?
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 are affected by CVE-2018-15774.
What is the severity of CVE-2018-15774?
CVE-2018-15774 has a severity rating of 8.8 (high).
How can CVE-2018-15774 be exploited?
An authenticated malicious iDRAC user with operator privileges could potentially exploit a permissions check flaw in the RACADM command-line utility.
How do I fix CVE-2018-15774?
To fix CVE-2018-15774, update your Dell iDRAC firmware to version 2.61.60.60 (for iDRAC7/iDRAC8) or 3.20.21.20 (for iDRAC9) or later.