CVE-2021-21544
2.7LOW
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 30 April 2021
Summary
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to any user.
Affected Version(s)
Integrated Dell Remote Access Controller (iDRAC) < 4.40.00.00
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved