Reflected Cross-Site Scripting Vulnerability in Dell EMC iDRAC9 Web Application
CVE-2020-26198
6.1MEDIUM
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 16 December 2020
Summary
The Dell EMC iDRAC9 web application prior to versions 4.32.10.00 and 4.40.00.00 is susceptible to a reflected cross-site scripting vulnerability. This issue allows remote attackers to execute malicious HTML or JavaScript in the context of a victim's browser. By deceiving users into clicking on a specially crafted link, an attacker could potentially compromise user sessions or redirect victims to malicious sites. It’s crucial for organizations using affected versions to update to prevent exploitation.
Affected Version(s)
Integrated Dell Remote Access Controller (iDRAC) < 4.32.10.00 and 4.40.00.00
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved