CVE-2020-5344: Buffer Overflow
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell EMC iDRAC7, iDRAC8 and iDRAC9to a version that resolves this vulnerability.Fixed in 2.65.65.65 - Upgrade
Upgrade
Dell EMC iDRAC7, iDRAC8 and iDRAC9to a version that resolves this vulnerability.Fixed in 2.70.70.70 - Upgrade
Upgrade
Dell EMC iDRAC7, iDRAC8 and iDRAC9to a version that resolves this vulnerability.Fixed in 4.00.00.00
Event History
Frequently Asked Questions
What is CVE-2020-5344?
CVE-2020-5344 is a stack-based buffer overflow vulnerability in Dell EMC iDRAC7, iDRAC8, and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, and 4.00.00.00.
What is the severity of CVE-2020-5344?
The severity of CVE-2020-5344 is rated as critical, with a severity value of 9.8.
How can an attacker exploit CVE-2020-5344?
An unauthenticated remote attacker can exploit CVE-2020-5344 to crash the affected process or execute arbitrary code on the system by sending specially crafted requests.
What is the affected software for CVE-2020-5344?
The affected software includes Dell EMC iDRAC7, iDRAC8, and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, and 4.00.00.00.
How to fix CVE-2020-5344?
To fix CVE-2020-5344, users should update their Dell EMC iDRAC7, iDRAC8, and iDRAC9 firmware to version 2.65.65.65, 2.70.70.70, or 4.00.00.00, respectively.