Vulnerabilities > CVE-2020-5344 - Out-of-bounds Write vulnerability in Dell Idrac7 Firmware, Idrac8 Firmware and Idrac9 Firmware

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
dell
CWE-787
critical
nessus

Summary

Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.

Common Weakness Enumeration (CWE)

Nessus

NASL familyCGI abuses
NASL idDRAC_DSA-2020-063.NASL
descriptionThe remote host is running iDRAC7 with a firmware version prior to 2.65.65.65, or iDRAC8 with a firmware version prior to 2.70.70.70, or iDRAC9 with a firmware version prior to 4.00.00.00 and is therefore affected by an buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data. Note that Nessus has not tested for this issue but has instead relied only on the application
last seen2020-05-21
modified2020-04-03
plugin id135187
published2020-04-03
reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/135187
titleDell iDRAC Buffer Overflow Vulnerability (CVE-2020-5344)