CVE-2018-15774
iDRAC7/iDRAC8/iDRAC9 - Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with operator privileges could potentially exploit a permissions check flaw in the Redfish interface to gain administrator access.
Dell EMC iDRAC7/iDRAC8, en versiones anteriores a la 2.61.60.60, y iDRAC9 en versiones anteriores a la 3.20.21.20, 3.21.24.22, 3.21.26.22 y 3.23.23.23, contienen una vulnerabilidad de escalado de privilegios. Un usuario iDRAC malicioso autenticado con privilegios de operador podrÃa explotar un error de comprobación de permisos en la interfaz Redfish para obtener acceso de administrador.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-08-23 CVE Reserved
- 2018-12-13 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106233 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Idrac7 Firmware Search vendor "Dell" for product "Idrac7 Firmware" | < 2.61.60.60 Search vendor "Dell" for product "Idrac7 Firmware" and version " < 2.61.60.60" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Idrac8 Firmware Search vendor "Dell" for product "Idrac8 Firmware" | < 2.61.60.60 Search vendor "Dell" for product "Idrac8 Firmware" and version " < 2.61.60.60" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Idrac9 Firmware Search vendor "Dell" for product "Idrac9 Firmware" | < 3.20.21.20 Search vendor "Dell" for product "Idrac9 Firmware" and version " < 3.20.21.20" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Idrac9 Firmware Search vendor "Dell" for product "Idrac9 Firmware" | >= 3.21.21.21 < 3.21.24.22 Search vendor "Dell" for product "Idrac9 Firmware" and version " >= 3.21.21.21 < 3.21.24.22" | - |
Affected
|