CVE-2021-21540: High severity dell emc idrac9 firmware vulnerability
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a stack-based overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to overwrite configuration information by injecting arbitrarily large payload.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21540?
CVE-2021-21540 is a vulnerability in Dell EMC iDRAC9 versions prior to 4.40.00.00 that allows a remote authenticated attacker to overwrite configuration information.
How does CVE-2021-21540 affect Dell EMC iDRAC9?
CVE-2021-21540 affects Dell EMC iDRAC9 versions prior to 4.40.00.00 and allows a remote authenticated attacker to exploit a stack-based overflow vulnerability.
What is the severity of CVE-2021-21540?
The severity of CVE-2021-21540 is high with a CVSS score of 8.1.
How can CVE-2021-21540 be exploited?
CVE-2021-21540 can be exploited by a remote authenticated attacker injecting a large payload to overwrite configuration information.
Is there a fix available for CVE-2021-21540?
Yes, Dell has released a fix for CVE-2021-21540. It is recommended to update to iDRAC9 version 4.40.00.00 or later.