Improper Input Validation in Dell iDRAC8 Product
CVE-2022-34436

2.7LOW

Key Information:

Vendor
Dell
Vendor
CVE Published:
18 January 2023

Summary

The Dell iDRAC8, specifically versions 2.83.83.83 and earlier, suffers from an improper input validation vulnerability within Racadm when the firmware lockdown configuration is enabled. This flaw potentially allows a remote attacker with high privileges to circumvent the firmware lockdown settings, thus enabling unauthorized firmware updates. Such exploitation could lead to compromised device integrity and unauthorized changes to system configurations.

Affected Version(s)

Integrated Dell Remote Access Controller 8 0 <= 2.83.83.83

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.