First published: Fri Apr 26 2019(Updated: )
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Idrac9 Firmware | =3.20.21.20 | |
Dell Idrac9 Firmware | =3.21.24.22 | |
Dell Idrac9 Firmware | =3.23.23.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3706 is a vulnerability in Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22, and 3.21.25.22 that allows an attacker to bypass authentication and gain unauthorized access to the system.
CVE-2019-3706 is considered critical, with a severity rating of 9.8.
An attacker can exploit CVE-2019-3706 by sending specially crafted data to the iDRAC web interface, bypassing authentication and gaining unauthorized access to the system.
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22, and 3.21.25.22 are affected by CVE-2019-3706.
To fix CVE-2019-3706, update your Dell EMC iDRAC9 firmware to version 3.24.24.24, 3.21.26.22, 3.22.22.22, or 3.21.25.22 by following the instructions provided by Dell.