First published: Tue Mar 31 2020(Updated: )
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Idrac7 Firmware | <2.65.65.65 | |
Dell iDRAC7 | ||
Dell Idrac8 Firmware | <2.70.70.70 | |
Dell iDRAC8 | ||
Dell Idrac9 Firmware | <4.00.00.00 | |
Dell iDRAC9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5344 is a stack-based buffer overflow vulnerability in Dell EMC iDRAC7, iDRAC8, and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, and 4.00.00.00.
The severity of CVE-2020-5344 is rated as critical, with a severity value of 9.8.
An unauthenticated remote attacker can exploit CVE-2020-5344 to crash the affected process or execute arbitrary code on the system by sending specially crafted requests.
The affected software includes Dell EMC iDRAC7, iDRAC8, and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, and 4.00.00.00.
To fix CVE-2020-5344, users should update their Dell EMC iDRAC7, iDRAC8, and iDRAC9 firmware to version 2.65.65.65, 2.70.70.70, or 4.00.00.00, respectively.