First published: Wed Dec 16 2020(Updated: )
Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC iDRAC9 Firmware | <=4.32.10.00 | |
Dell EMC iDRAC9 Firmware | =4.40.00.00 | |
Dell iDRAC9 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26198 is classified as a high severity reflected cross-site scripting vulnerability.
To fix CVE-2020-26198, upgrade to iDRAC9 firmware versions 4.32.10.00 or 4.40.00.00 or later.
CVE-2020-26198 affects Dell EMC iDRAC9 firmware versions prior to 4.32.10.00 and 4.40.00.00.
Yes, CVE-2020-26198 can be exploited remotely by tricking a victim into following a malicious link.
CVE-2020-26198 is associated with reflected cross-site scripting (XSS) attacks.