CVE-2019-3705
Buffer Overflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or execute arbitrary code on the system with privileges of the webserver by sending specially crafted input data to the affected system.
iDRAC6 de Dell EMC en versiones anteriores a la 2.92, iDRAC7/iDRAC8 en versiones anteriores a la 2.61.60.60 y iDRAC9 en versiones anteriores a la 3.20.21.20, 3.21.24.22, 3.21.26.22 y 3.23.23.23 contienen una vulnerabilidad de desbordamiento de búfer basada en pila. Un atacante remoto no autenticado puede explotar esta vulnerabilidad para bloquear el servidor web o ejecutar código arbitrario en el sistema con privilegios del servidor web enviando datos de entrada especialmente diseñados al sistema afectado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2019-03-03 CVE Published
- 2023-06-05 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Idrac6 Firmware Search vendor "Dell" for product "Idrac6 Firmware" | < 2.92 Search vendor "Dell" for product "Idrac6 Firmware" and version " < 2.92" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Idrac7 Firmware Search vendor "Dell" for product "Idrac7 Firmware" | < 2.61.60.60 Search vendor "Dell" for product "Idrac7 Firmware" and version " < 2.61.60.60" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Idrac8 Firmware Search vendor "Dell" for product "Idrac8 Firmware" | < 2.61.60.60 Search vendor "Dell" for product "Idrac8 Firmware" and version " < 2.61.60.60" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Idrac9 Firmware Search vendor "Dell" for product "Idrac9 Firmware" | < 3.20.21.20 Search vendor "Dell" for product "Idrac9 Firmware" and version " < 3.20.21.20" | - |
Affected
|