First published: Wed Jan 18 2023(Updated: )
Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Idrac8 Firmware | <2.84.84.84 | |
Dell iDRAC8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Dell iDRAC8 vulnerability is CVE-2022-34436.
The severity of CVE-2022-34436 is medium.
The affected software for CVE-2022-34436 is Dell iDRAC8 firmware version 2.83.83.83 and prior.
The impact of CVE-2022-34436 is that a remote high privileged attacker could bypass the firmware lock-down configuration and perform a firmware update.
To fix CVE-2022-34436, update to Dell iDRAC8 firmware version 2.84.84.84.