Dell EMC iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for certain URLs. A man-in-the-middle attacker could use this vulnerability to strip the SSL/TLS protection from a connection between a client and a server.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: dell
Published: 2018-07-02T17:00:00Z
Updated: 2024-09-17T03:19:03.618Z
Reserved: 2017-12-06T00:00:00
Link: CVE-2018-1249
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-07-02T17:29:00.427
Modified: 2024-11-21T03:59:27.833
Link: CVE-2018-1249
Redhat
No data.