CVE-2021-36299
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to the affected application.
Dell iDRAC9 versiones 4.40.00.00 y posteriores, pero anteriores a 4.40.29.00 y 5.00.00.00, contienen una vulnerabilidad de inyección SQL. Un usuario malicioso autenticado y con pocos privilegios puede explotar potencialmente esta vulnerabilidad para causar la divulgación de información o una denegación de servicio mediante el suministro de datos de entrada especialmente diseñados a la aplicación afectada
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-08 CVE Reserved
- 2021-11-23 CVE Published
- 2023-06-16 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.emc.com/kb/000191229 | 2021-11-27 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Emc Idrac9 Firmware Search vendor "Dell" for product "Emc Idrac9 Firmware" | >= 4.40.00.00 < 4.40.29.00 Search vendor "Dell" for product "Emc Idrac9 Firmware" and version " >= 4.40.00.00 < 4.40.29.00" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Idrac9 Firmware Search vendor "Dell" for product "Emc Idrac9 Firmware" | 5.00.00.00 Search vendor "Dell" for product "Emc Idrac9 Firmware" and version "5.00.00.00" | - |
Affected
|