CVE-2018-1212 PUBLISHED CVSS 8.800000190734863 HIGH

The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected iDRAC system.

EPSS 0.89% · 75.3th percentile

Risk Scores

CVSS v3.0
8.800000190734863
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.89%
75.3th percentile

Affected Products

VendorProductVersions
dellidrac6_modular
Dell EMCiDRAC6 (Monolithic)unspecified
dellidrac6_monolithic0
Dell EMCiDRAC6 (Modular)unspecified

Timeline

References

Open in Interactive Console →