The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected iDRAC system.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11846 | The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected iDRAC system. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T01:37:02.877Z
Reserved: 2017-12-06T00:00:00.000Z
Link: CVE-2018-1212
No data.
Status : Modified
Published: 2018-07-02T17:29:00.257
Modified: 2024-11-21T03:59:24.007
Link: CVE-2018-1212
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD