SB2022012658 - Stack-based buffer overflow in Dell iDRAC9 and Dell iDRAC8



SB2022012658 - Stack-based buffer overflow in Dell iDRAC9 and Dell iDRAC8

Published: January 26, 2022 Updated: August 10, 2022

Security Bulletin ID SB2022012658
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Stack-based buffer overflow (CVE-ID: CVE-2021-36347)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. An authenticated remote user with high privileges can exploit this vulnerability to control process execution and gain access to the iDRAC operating system.


Remediation

Install update from vendor's website.