Improper Authorization in iDRAC8 and iDRAC9 - CVE-2019-3764
Published: November 15, 2019
Vulnerability identifier: #VU22789
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3764
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to missing authorization checks. A remote authenticated attacker can obtain sensitive information such as password hashes.
Affected software
iDRAC8
iDRAC9
iDRAC7
EMC Integrated Data Protection Appliance
VxFlex OS
VCF over VxRail
VxRail Manager
iDRAC9
iDRAC7
EMC Integrated Data Protection Appliance
VxFlex OS
VCF over VxRail
VxRail Manager
How to mitigate CVE-2019-3764
Install updates from vendor's website.
iDRAC8 - update to 2.70.70.70
iDRAC9 - update to 3.36.36.36
iDRAC7 - update to 2.65.65.65
VxFlex OS - update to 3.0.1.1
VCF over VxRail - update to 3.9.1
VxRail Manager - addressed in versions 4.0.600, 4.5.401, 4.7.301
iDRAC9 - update to 3.36.36.36
iDRAC7 - update to 2.65.65.65
VxFlex OS - update to 3.0.1.1
VCF over VxRail - update to 3.9.1
VxRail Manager - addressed in versions 4.0.600, 4.5.401, 4.7.301
External References
Related Security Bulletins
- Improper Authorization in Dell EMC iDRAC8 and iDRAC9
- Multiple vulnerabilities in Dell EMC Integrated Data Protection Appliance
- Improper authorization in Dell EMC VxFlex OS
- Improper authorization in Dell EMC VCF over VxRail
- Improper authorization in Dell EMC VxRail Manager
- Improper authorization in Dell iDRAC7