ZeroHour

CVE-2018-15774

CVSS 3.0
8.8 high
EPSS
<1%p59
Published
()
Modified
Description

Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with operator privileges could potentially exploit a permissions check flaw in the Redfish interface to gain administrator access.

Vendors
dell
Products
idrac7 firmware, idrac8 firmware, idrac9 firmware
Weakness
CWE-863
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.