First published: Thu May 06 2021(Updated: )
Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Integrated System for Microsoft Azure Stack Hub Firmware | >=1906<=2011 | |
Microsoft Azure Stack Hub |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21505 has a moderate severity level due to the possibility of remote unauthenticated access to the iDRAC interface.
To fix CVE-2021-21505, change the default iDRAC credentials to strong, unique passwords.
CVE-2021-21505 affects users of Dell EMC Integrated System for Microsoft Azure Stack Hub versions 1906 through 2011.
Yes, CVE-2021-21505 can be exploited remotely by an attacker who knows the default iDRAC credentials.
An attacker exploiting CVE-2021-21505 could gain root privileges on the affected Dell EMC Integrated System.