Improper Neutralization of Special Elements in Output Used by a Downstream Component in iDRAC9 and iDRAC8 - CVE-2021-21580

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in iDRAC9 and iDRAC8 - CVE-2021-21580

Published: April 27, 2022


Vulnerability identifier: #VU62645
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21580
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a Content spoofing / Text injection. A remote attacker can inject text to present a customized message on the application and phish users into believing that the message is legitimate.


Affected software

iDRAC9
iDRAC8
EMC ECS
Dell EMC VxRail Appliance
PowerScale OneFS

How to mitigate CVE-2021-21580

Install updates from vendor's website.

iDRAC9 - update to 5.00.00.00
iDRAC8 - update to 2.80.80.80
Dell EMC VxRail Appliance - update to 7.0.300
PowerScale OneFS - update to 11.7

External References

Related Security Bulletins