CVE-2021-21505: Critical severity dell emc integrated system for microsoft azure stack hub firmware vulnerability
Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21505?
CVE-2021-21505 has a moderate severity level due to the possibility of remote unauthenticated access to the iDRAC interface.
How do I fix CVE-2021-21505?
To fix CVE-2021-21505, change the default iDRAC credentials to strong, unique passwords.
Who is affected by CVE-2021-21505?
CVE-2021-21505 affects users of Dell EMC Integrated System for Microsoft Azure Stack Hub versions 1906 through 2011.
Can CVE-2021-21505 be exploited remotely?
Yes, CVE-2021-21505 can be exploited remotely by an attacker who knows the default iDRAC credentials.
What could an attacker achieve using CVE-2021-21505?
An attacker exploiting CVE-2021-21505 could gain root privileges on the affected Dell EMC Integrated System.