CVE-2018-1244
—CVSS 3.0
8.8 high
EPSS
3%p88
Published
()
Modified
Description
Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious iDRAC user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC where SNMP alerting is enabled.
- Vendors
- dell
- Products
- idrac7 firmware, idrac8 firmware, idrac9 firmware
- Weakness
- CWE-77
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.