CVE-2022-24422: Critical severity dell idrac9 firmware vulnerability
Published May 26, 2022
·Updated
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console.
Affected Software
1 affected component
Dell iDRAC9>=5.00.00.00<5.10.10.00
Remediation
Event History
May 26, 2022
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-24422.
2
What is the severity of CVE-2022-24422?
The severity of CVE-2022-24422 is critical with a CVSS score of 9.8.
3
Which Dell iDRAC9 versions are affected by CVE-2022-24422?
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00 are affected by CVE-2022-24422.
4
How can an attacker exploit CVE-2022-24422?
A remote unauthenticated attacker may potentially exploit CVE-2022-24422 to gain access to the VNC Console.
5
Where can I find more information about CVE-2022-24422?
You can find more information about CVE-2022-24422 at the following link: https://www.dell.com/support/kbdoc/en-us/000199267/dsa-2022-068-dell-idrac9-security-update-for-an-improper-authentication-vulnerability