Known vulnerabilities in iDRAC8

Vendor: Dell
Software: iDRAC8
Software CPE: cpe:2.3:a:dell:idrac8:*:*:*:*:*:*:*:*
Total vulnerabilities: 22
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting iDRAC8 iDRAC8 is affected by 22 known vulnerabilities: 4 high, 5 medium, 13 low Critical High Medium Low

Vulnerabilities (22)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU75575 - Permissions, Privileges, and Access Controls
CVE-2022-34436
CWE-264 Medium
No
No
2.84.84.84 28.04.2023 SB2023042804
#VU66164 - Stack-based buffer overflow
CVE-2021-36347
CWE-121 Low
No
No
2.82.82.82 08.08.2022 SB2022012658
SB2022092810
SB2023010516
and 1 more
#VU66163 - Improper input validation
CVE-2021-36346
CWE-20 Medium
Available
No
2.82.82.82, 2.80.80.80 08.08.2022 SB2022092810
SB2022111803
SB2023010516
#VU62645 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2021-21580
CWE-74 Low
No
No
2.80.80.80 27.04.2022 SB2021080330
SB2022042707
SB2022111726
and 1 more
#VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-0778
CWE-835 Medium
Available
No
2.83.83.83 15.03.2022 SB2022031520
SB2022031522
SB2022031611
and 238 more
#VU56064 - Out-of-bounds read
CVE-2021-3712
CWE-125 Medium
No
No
2.80.80.80 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 142 more
#VU26517 - Stack-based buffer overflow
CVE-2020-5344
CWE-121 High
No
No
2.70.70.70 01.04.2020 SB2020040154
SB2022080311
SB2022102631
and 1 more
#VU22789 - Improper Authorization
CVE-2019-3764
CWE-285 Medium
No
No
2.70.70.70 15.11.2019 SB2019110725
SB2022102631
SB2022110116
and 3 more
#VU17812 - Buffer overflow
CVE-2015-7272
CWE-120 Low
No
No
2.21.21.21 21.02.2019 SB2015120201
#VU17811 - Permissions, Privileges, and Access Controls
CVE-2015-7271
CWE-264 Low
No
No
2.21.21.21 21.02.2019 SB2015120201
#VU17810 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2015-7270
CWE-22 Low
No
No
2.21.21.21 21.02.2019 SB2015120201
#VU17809 - Command injection
CVE-2018-1243
CWE-77 Low
No
No
2.60.60.60 21.02.2019 SB2018070210
#VU17808 - Command injection
CVE-2018-1244
CWE-77 Low
No
No
2.60.60.60 21.02.2019 SB2018070210
#VU16673 - Error Handling
CVE-2018-15776
CWE-388 Low
No
No
2.61.60.60 24.12.2018 SB2018122404
#VU16672 - Permissions, Privileges, and Access Controls
CVE-2018-15774
CWE-264 Low
No
No
2.61.60.60 24.12.2018 SB2018122404
#VU12133 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-1211
CWE-22 Low
No
No
2.52.52.52 24.04.2018 SB2018042416
#VU12132 - Command injection
CVE-2018-1207
CWE-77 High
Available
No
2.52.52.52 24.04.2018 SB2018042416
#VU12103 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2016-5685
CWE-74 Low
No
No
2.40.40.40 23.04.2018 SB2016111606
#VU11081 - Improper Handling of Values
CVE-2018-1000116
CWE-229 High
No
No
2.52.52.52 14.03.2018 SB2018010928
SB2018032814
SB2018042416
and 4 more
#VU638 - Buffer overflow
CVE-2016-2108
CWE-120 High
No
No
2.30.30.30 23.09.2016 SB2018011609
SB2016051804
SB2016053102
and 28 more


Showing elements 1 - 20 out of 22