Open Redirect Vulnerability in Dell EMC iDRAC9 Products
CVE-2021-21578

6.1MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
3 August 2021

Summary

Dell EMC iDRAC9 prior to version 4.40.40.00 is susceptible to an open redirect vulnerability that allows remote unauthenticated attackers to manipulate URLs. By crafting deceptive links, attackers can trick users into clicking, leading them to potentially harmful external sites, thus posing a significant threat to the security of affected systems.

Affected Version(s)

Integrated Dell Remote Access Controller (iDRAC) < 4.40.40.00

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.