CVE-2021-21544: Medium severity dell emc idrac9 firmware vulnerability
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to any user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21544?
CVE-2021-21544 is an improper authentication vulnerability in Dell EMC iDRAC9 versions prior to 4.40.00.00.
How does CVE-2021-21544 affect Dell EMC iDRAC9?
CVE-2021-21544 allows a remote authenticated malicious user to manipulate the username field under the comment section and set the value to any user.
What is the severity of CVE-2021-21544?
The severity of CVE-2021-21544 is medium with a CVSS score of 2.7.
Which versions of Dell EMC iDRAC9 are affected by CVE-2021-21544?
Dell EMC iDRAC9 versions prior to 4.40.00.00 are affected by CVE-2021-21544.
How can I fix CVE-2021-21544?
To fix CVE-2021-21544, update Dell EMC iDRAC9 firmware to version 4.40.00.00 or later.