Vulnerabilities > CVE-2018-15776 - Unspecified vulnerability in Dell Idrac7 Firmware and Idrac8 Firmware
Attack vector
PHYSICAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to get access to the u-boot shell.
Vulnerable Configurations
Nessus
NASL family | CGI abuses |
NASL id | DRAC_2018_12_13.NASL |
description | The remote host is running iDRAC7 or iDRAC8 with a firmware version prior to 2.61.60.60, or iDRAC9 with a firmware version prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 or 3.23.23.23 and is therefore affected by the following vulnerabilities: - An elevation of privilege vulnerability exists in Redfish interface. An authenticated, attacker can exploit, via a permissions check flaw, to gain elevated privileges. (CVE-2018-15774) - A flaw exists in iDRAC7 / iDRAC8 due to improper handling of an error. A unauthenticated, remote attacker can exploit this to gain access to a u-boot shell. (CVE-2018-15776) |
last seen | 2020-05-21 |
modified | 2018-12-21 |
plugin id | 119833 |
published | 2018-12-21 |
reporter | This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/119833 |
title | Dell iDRAC Products Multiple Vulnerabilities (December 2018) |
code |
|
References
- http://www.securityfocus.com/bid/106233
- http://www.securityfocus.com/bid/106233
- https://www.dell.com/support/article/us/en/19/sln315190/dell-emc-idrac-multiple-vulnerabilities-cve-2018-15774-and-cve-2018-15776-?lang=en
- https://www.dell.com/support/article/us/en/19/sln315190/dell-emc-idrac-multiple-vulnerabilities-cve-2018-15774-and-cve-2018-15776-?lang=en