CVE-2019-3706: Web Interface Authentication Bypass Vulnerability
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3706?
CVE-2019-3706 is a vulnerability in Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22, and 3.21.25.22 that allows an attacker to bypass authentication and gain unauthorized access to the system.
How severe is CVE-2019-3706?
CVE-2019-3706 is considered critical, with a severity rating of 9.8.
How can an attacker exploit CVE-2019-3706?
An attacker can exploit CVE-2019-3706 by sending specially crafted data to the iDRAC web interface, bypassing authentication and gaining unauthorized access to the system.
Which versions of Dell EMC iDRAC9 are affected by CVE-2019-3706?
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22, and 3.21.25.22 are affected by CVE-2019-3706.
How do I fix CVE-2019-3706?
To fix CVE-2019-3706, update your Dell EMC iDRAC9 firmware to version 3.24.24.24, 3.21.26.22, 3.22.22.22, or 3.21.25.22 by following the instructions provided by Dell.