ZeroHour

CVE-2021-21505

CVSS 3.1
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.

Vendors
dell
Products
emc integrated system for microsoft azure stack hub firmware
Weakness
CWE-255, CWE-1188
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.