Improper Authorization in iDRAC8 and iDRAC9 - CVE-2019-3764

 

Improper Authorization in iDRAC8 and iDRAC9 - CVE-2019-3764

Published: November 15, 2019


Vulnerability identifier: #VU22789
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3764
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to missing authorization checks. A remote authenticated attacker can obtain sensitive information such as password hashes.



Affected software

iDRAC8
iDRAC9
iDRAC7
EMC Integrated Data Protection Appliance
VxFlex OS
VCF over VxRail
VxRail Manager

How to mitigate CVE-2019-3764

Install updates from vendor's website.

iDRAC8 - update to 2.70.70.70
iDRAC9 - update to 3.36.36.36
iDRAC7 - update to 2.65.65.65
VxFlex OS - update to 3.0.1.1
VCF over VxRail - update to 3.9.1
VxRail Manager - addressed in versions 4.0.600, 4.5.401, 4.7.301

External References

Related Security Bulletins