CVE-2018-1212

The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected iDRAC system.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:idrac6_monolithic:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:idrac6_modular:*:*:*:*:*:*:*:*

Information

Published : 2018-07-02 10:29

Updated : 2019-10-09 16:38


NVD link : CVE-2018-1212

Mitre link : CVE-2018-1212


JSON object : View

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Advertisement

dedicated server usa

Products Affected

dell

  • idrac6_monolithic
  • idrac6_modular