CVE-2021-36300: SQL Injection
iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability by sending a specially crafted malicious request to crash the webserver or cause information disclosure.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36300?
CVE-2021-36300 is classified as a high severity vulnerability due to its potential for unauthorized remote exploitation.
How do I fix CVE-2021-36300?
To remediate CVE-2021-36300, update your Dell iDRAC9 firmware to version 5.00.00.00 or later.
What could an attacker achieve by exploiting CVE-2021-36300?
An attacker exploiting CVE-2021-36300 may be able to crash the webserver or gain unauthorized access to sensitive information.
Which versions of iDRAC9 are affected by CVE-2021-36300?
CVE-2021-36300 affects all iDRAC9 firmware versions prior to 5.00.00.00.
Is authentication required to exploit CVE-2021-36300?
No, CVE-2021-36300 can be exploited by an unauthenticated remote attacker.