Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.
References
Configurations
Information
Published : 2021-03-08 14:15
Updated : 2022-10-24 10:08
NVD link : CVE-2021-21510
Mitre link : CVE-2021-21510
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
dell
- idrac8_firmware