Reflected Cross-Site Scripting Vulnerability in Dell EMC iDRAC9 Web Application
CVE-2020-26198

6.1MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
16 December 2020

Summary

The Dell EMC iDRAC9 web application prior to versions 4.32.10.00 and 4.40.00.00 is susceptible to a reflected cross-site scripting vulnerability. This issue allows remote attackers to execute malicious HTML or JavaScript in the context of a victim's browser. By deceiving users into clicking on a specially crafted link, an attacker could potentially compromise user sessions or redirect victims to malicious sites. It’s crucial for organizations using affected versions to update to prevent exploitation.

Affected Version(s)

Integrated Dell Remote Access Controller (iDRAC) < 4.32.10.00 and 4.40.00.00

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.