Brute-force attack in Dell products - CVE-2018-1243

 

Brute-force attack in Dell products - CVE-2018-1243

Published: February 21, 2019


Vulnerability identifier: #VU17809
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1243
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows remote attacker to perform brute-force attack on the target system.

The vulnerability exists due to the sessions invoked via CGI binaries use 96-bit numeric-only session ID values. A remote attacker can perform bruteforce session guessing attacks.

Successful exploitation of this vulnerability may result in unauthorized access to the system.

Affected software

iDRAC6
iDRAC8
iDRAC7
iDRAC9

How to mitigate CVE-2018-1243

Install updates from vendor's website.

iDRAC6 - update to 2.91
iDRAC8 - update to 2.60.60.60
iDRAC7 - update to 2.60.60.60
iDRAC9 - update to 3.21.21.21

External References

Related Security Bulletins