CVE-2018-15776: iDRAC7, iDRAC8 - Improper Error Handling
Published Dec 13, 2018
·Updated
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to get access to the u-boot shell.
Affected Software
2 affected components
Dell Idrac7 Firmware<2.61.60.60
Dell Idrac8 Firmware<2.61.60.60
Event History
Dec 13, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2018-15776?
CVE-2018-15776 is an improper error handling vulnerability in Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60.
2
What is the severity of CVE-2018-15776?
The severity of CVE-2018-15776 is medium with a severity value of 6.8.
3
How can an attacker exploit CVE-2018-15776?
An unauthenticated attacker with physical access to the system can potentially exploit CVE-2018-15776 to gain access to the u-boot shell.
4
Which software versions are affected by CVE-2018-15776?
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 are affected by CVE-2018-15776.
5
How can I fix CVE-2018-15776?
To fix CVE-2018-15776, update your Dell EMC iDRAC7/iDRAC8 firmware to version 2.61.60.60 or later.