CVE-2018-1244
iDRAC7/iDRAC8/iDrac9 contains a command injection vulnerability in the SNMP agent.
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious iDRAC user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC where SNMP alerting is enabled.
Dell EMC iDRAC7/iDRAC8, en versiones anteriores a la 2.60.60.60, y iDRAC9 en versiones anteriores a la 3.21.21.21, contienen una vulnerabilidad de inyección de comandos en el agente SNMP. Un usuario iDRAC autenticado remoto con privilegios de configuración podría explotar esta vulnerabilidad para ejecutar comandos arbitrarios en el iDRAC donde las alertas SNMP están habilitadas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-06 CVE Reserved
- 2018-07-02 CVE Published
- 2024-08-21 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104964 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://en.community.dell.com/techcenter/extras/m/white_papers/20487494 | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Idrac7 Firmware Search vendor "Dell" for product "Idrac7 Firmware" | < 2.60.60.60 Search vendor "Dell" for product "Idrac7 Firmware" and version " < 2.60.60.60" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Idrac8 Firmware Search vendor "Dell" for product "Idrac8 Firmware" | < 2.60.60.60 Search vendor "Dell" for product "Idrac8 Firmware" and version " < 2.60.60.60" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Idrac9 Firmware Search vendor "Dell" for product "Idrac9 Firmware" | < 3.21.21.21 Search vendor "Dell" for product "Idrac9 Firmware" and version " < 3.21.21.21" | - |
Affected
|