CVE-2022-34436: Input Validation
Published Jan 18, 2023
·Updated
Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.
Affected Software
2 affected components
Dell Idrac8 Firmware<2.84.84.84
Dell iDRAC8
Remediation
Event History
Jan 18, 2023
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Dell iDRAC8 vulnerability?
The vulnerability ID of this Dell iDRAC8 vulnerability is CVE-2022-34436.
2
What is the severity of CVE-2022-34436?
The severity of CVE-2022-34436 is medium.
3
What is the affected software for CVE-2022-34436?
The affected software for CVE-2022-34436 is Dell iDRAC8 firmware version 2.83.83.83 and prior.
4
What is the impact of CVE-2022-34436?
The impact of CVE-2022-34436 is that a remote high privileged attacker could bypass the firmware lock-down configuration and perform a firmware update.
5
How can I fix CVE-2022-34436?
To fix CVE-2022-34436, update to Dell iDRAC8 firmware version 2.84.84.84.