CVE-2021-21543: XSS
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges could potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected parameters. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21543?
CVE-2021-21543 is a vulnerability in Dell EMC iDRAC9 versions prior to 4.40.00.00 that allows for multiple stored cross-site scripting (XSS) attacks.
How can a malicious user exploit CVE-2021-21543?
A remote authenticated malicious user with high privileges could exploit CVE-2021-21543 to store malicious HTML or JavaScript code through multiple affected parameters.
What is the severity of CVE-2021-21543?
CVE-2021-21543 has a severity rating of 4.8 out of 10, which is considered medium.
Which software versions are affected by CVE-2021-21543?
Dell EMC iDRAC9 versions prior to 4.40.00.00 are affected by CVE-2021-21543.
How can I fix CVE-2021-21543?
To fix CVE-2021-21543, it is recommended to update to version 4.40.00.00 or later of Dell EMC iDRAC9 firmware.