Vulnerabilities > Dell > Integrated Remote Access Controller 6

DATE CVE VULNERABILITY TITLE RISK
2017-04-10 CVE-2015-7275 Cross-site Scripting vulnerability in Dell Integrated Remote Access Controller Firmware
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.
network
dell CWE-79
4.3
2017-04-10 CVE-2015-7274 Permissions, Privileges, and Access Controls vulnerability in Dell Integrated Remote Access Controller Firmware
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands.
network
low complexity
dell CWE-264
6.5
2017-04-10 CVE-2015-7272 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell Integrated Remote Access Controller Firmware
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long SSH username or input.
network
low complexity
dell CWE-119
7.5
2017-04-10 CVE-2015-7270 Path Traversal vulnerability in Dell Integrated Remote Access Controller Firmware
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.
local
low complexity
dell CWE-22
4.6