CVE-2024-22428: High severity Dell EMC iDRAC Service Module vulnerability
Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell iDRAC Service Moduleto a version that resolves this vulnerability.Fixed in 5.2.0.0 and prior
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22428?
CVE-2024-22428 is classified as a high severity vulnerability due to its potential for privilege escalation and arbitrary code execution.
How do I fix CVE-2024-22428?
To fix CVE-2024-22428, upgrade the Dell iDRAC Service Module to version 5.2.0.1 or later at your earliest convenience.
Who is affected by CVE-2024-22428?
CVE-2024-22428 affects users of the Dell EMC iDRAC Service Module versions up to and including 5.2.0.0.
What type of vulnerability is CVE-2024-22428?
CVE-2024-22428 is categorized as an Incorrect Default Permissions vulnerability.
Can CVE-2024-22428 be exploited remotely?
CVE-2024-22428 requires local access for exploitation, as it allows privilege escalation for unprivileged users.