Open Redirect Vulnerability in Dell EMC iDRAC9 Products
CVE-2021-21578
6.1MEDIUM
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 3 August 2021
Summary
Dell EMC iDRAC9 prior to version 4.40.40.00 is susceptible to an open redirect vulnerability that allows remote unauthenticated attackers to manipulate URLs. By crafting deceptive links, attackers can trick users into clicking, leading them to potentially harmful external sites, thus posing a significant threat to the security of affected systems.
Affected Version(s)
Integrated Dell Remote Access Controller (iDRAC) < 4.40.40.00
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved