Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-8811 Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-16T16:58:47.474Z

Reserved: 2021-01-04T00:00:00

Link: CVE-2021-21539

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-30T21:15:08.707

Modified: 2024-11-21T05:48:33.110

Link: CVE-2021-21539

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses