Arbitrary Command Execution Risk in Dell iDRAC Products
CVE-2014-8272
Currently unrated
What is CVE-2014-8272?
The IPMI 1.5 functionality in select Dell iDRAC versions fails to securely manage session ID values, enabling remote attackers to potentially execute arbitrary commands via brute-force methods. This vulnerability affects multiple iDRAC versions, posing a serious security concern for systems relying on this management interface. To mitigate risks, users are advised to update to the latest firmware versions and implement additional security measures.