Known vulnerabilities in iDRAC7

Vendor: Dell
Software: iDRAC7
Software CPE: cpe:2.3:a:dell:idrac7:*:*:*:*:*:*:*:*
Total vulnerabilities: 17
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting iDRAC7 iDRAC7 is affected by 17 known vulnerabilities: 4 high, 1 medium, 12 low Critical High Medium Low

Vulnerabilities (17)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU26517 - Stack-based buffer overflow
CVE-2020-5344
CWE-121 High
No
No
2.65.65.65 01.04.2020 SB2020040154
SB2022080311
SB2022102631
and 1 more
#VU22789 - Improper Authorization
CVE-2019-3764
CWE-285 Medium
No
No
2.65.65.65 15.11.2019 SB2019110725
SB2022102631
SB2022110116
and 3 more
#VU17816 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2013-3589
CWE-79 Low
No
No
1.46.45 21.02.2019 SB2013092501
#VU17815 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-7275
CWE-79 Low
No
No
2.30.30.30 21.02.2019 SB2015120201
#VU17813 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2015-7273
CWE-611 Low
No
No
2.21.21.21 21.02.2019 SB2015120201
#VU17812 - Buffer overflow
CVE-2015-7272
CWE-120 Low
No
No
2.21.21.21 21.02.2019 SB2015120201
#VU17811 - Permissions, Privileges, and Access Controls
CVE-2015-7271
CWE-264 Low
No
No
2.21.21.21 21.02.2019 SB2015120201
#VU17810 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2015-7270
CWE-22 Low
No
No
2.21.21.21 21.02.2019 SB2015120201
#VU17809 - Command injection
CVE-2018-1243
CWE-77 Low
No
No
2.60.60.60 21.02.2019 SB2018070210
#VU17808 - Command injection
CVE-2018-1244
CWE-77 Low
No
No
2.60.60.60 21.02.2019 SB2018070210
#VU16673 - Error Handling
CVE-2018-15776
CWE-388 Low
No
No
2.61.60.60 24.12.2018 SB2018122404
#VU16672 - Permissions, Privileges, and Access Controls
CVE-2018-15774
CWE-264 Low
No
No
2.61.60.60 24.12.2018 SB2018122404
#VU12133 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-1211
CWE-22 Low
No
No
2.52.52.52 24.04.2018 SB2018042416
#VU12132 - Command injection
CVE-2018-1207
CWE-77 High
Available
No
2.52.52.52 24.04.2018 SB2018042416
#VU12103 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2016-5685
CWE-74 Low
No
No
2.40.40.40 23.04.2018 SB2016111606
#VU11081 - Improper Handling of Values
CVE-2018-1000116
CWE-229 High
No
No
2.52.52.52 14.03.2018 SB2018010928
SB2018032814
SB2018042416
and 4 more
#VU638 - Buffer overflow
CVE-2016-2108
CWE-120 High
No
No
2.30.30.30 23.09.2016 SB2018011609
SB2016051804
SB2016053102
and 28 more