CVE-2021-21539: Race Condition
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Dell EMC iDRAC9 vulnerability?
The vulnerability ID for this Dell EMC iDRAC9 vulnerability is CVE-2021-21539.
What is the severity rating of CVE-2021-21539?
The severity rating of CVE-2021-21539 is high with a score of 7.1.
What is the description of CVE-2021-21539?
CVE-2021-21539 is a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Dell EMC iDRAC9 versions prior to 4.40.00.00, which could allow a remote authenticated attacker to gain elevated privileges.
Which software versions are affected by CVE-2021-21539?
Dell EMC iDRAC9 versions prior to 4.40.00.00 are affected by CVE-2021-21539.
How can the vulnerability be fixed?
To fix CVE-2021-21539, users should update their Dell EMC iDRAC9 firmware to version 4.40.00.00 or newer.