First published: Tue Jan 25 2022(Updated: )
iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell iDRAC9 Firmware | <5.00.20.00 | |
Dell iDRAC9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36348 is classified as a medium-severity vulnerability due to its potential for information disclosure and denial of service.
To fix CVE-2021-36348, upgrade to iDRAC9 firmware version 5.00.20.00 or later.
CVE-2021-36348 affects users of iDRAC9 versions prior to 5.00.20.00 with remote authenticated access.
An attacker can exploit CVE-2021-36348 to conduct information disclosure or denial of service attacks by supplying crafted input.
Yes, CVE-2021-36348 specifically affects iDRAC9 firmware versions prior to 5.00.20.00.