First published: Fri Apr 30 2021(Updated: )
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to any user.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Idrac9 Firmware | <4.40.00.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21544 is an improper authentication vulnerability in Dell EMC iDRAC9 versions prior to 4.40.00.00.
CVE-2021-21544 allows a remote authenticated malicious user to manipulate the username field under the comment section and set the value to any user.
The severity of CVE-2021-21544 is medium with a CVSS score of 2.7.
Dell EMC iDRAC9 versions prior to 4.40.00.00 are affected by CVE-2021-21544.
To fix CVE-2021-21544, update Dell EMC iDRAC9 firmware to version 4.40.00.00 or later.