CVE-2022-34435: Input Validation
Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for Dell iDRAC9 firmware?
The vulnerability ID for Dell iDRAC9 firmware is CVE-2022-34435.
What is the severity of CVE-2022-34435?
The severity of CVE-2022-34435 is medium with a severity value of 4.9.
What is the affected software for CVE-2022-34435?
The affected software for CVE-2022-34435 is Dell iDRAC9 firmware version 6.00.02.00 and prior.
How does CVE-2022-34435 impact Dell iDRAC9 firmware?
CVE-2022-34435 allows a remote high privileged attacker to bypass the firmware lock-down configuration and perform a firmware update.
How can I fix CVE-2022-34435 in Dell iDRAC9 firmware?
To fix CVE-2022-34435 in Dell iDRAC9 firmware, it is recommended to update to version 6.00.30.00 or later.