SB2022012658 - Stack-based buffer overflow in Dell iDRAC9 and Dell iDRAC8
Published: January 26, 2022 Updated: August 10, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2021-36347)
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. An authenticated remote user with high privileges can exploit this vulnerability to control process execution and gain access to the iDRAC operating system.
Remediation
Install update from vendor's website.