Cross-Site Scripting Vulnerability in Dell EMC iDRAC9
CVE-2021-21581

6.5MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
3 August 2021

Summary

Dell EMC iDRAC9 prior to version 5.00.00.00 is affected by a cross-site scripting vulnerability. This flaw enables remote attackers to exploit the vulnerability by crafting a malicious link that, when followed by the victim, executes harmful HTML or JavaScript within the victim's browser. This can lead to unauthorized actions in the context of the user's session.

Affected Version(s)

Integrated Dell Remote Access Controller (iDRAC) < 5.00.00.00

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.