CVE-2021-21510: Input Validation
Published Mar 8, 2021
·Updated
Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.
Affected Software
1 affected component
Dell Idrac8 Firmware<2.75.100.75
Event History
Mar 8, 2021
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-21510?
CVE-2021-21510 is a host header injection vulnerability in Dell iDRAC8 versions prior to 2.75.100.75.
2
How can an attacker exploit CVE-2021-21510?
An attacker can potentially exploit CVE-2021-21510 by injecting arbitrary 'Host' header values to poison a web-cache or trigger redirections.
3
What is the severity of CVE-2021-21510?
CVE-2021-21510 has a severity rating of 6.1 (medium).
4
Which software versions are affected by CVE-2021-21510?
Dell iDRAC8 versions prior to 2.75.100.75 are affected by CVE-2021-21510.
5
How do I fix CVE-2021-21510?
To fix CVE-2021-21510, update Dell iDRAC8 firmware to version 2.75.100.75 or later.