Stack-based buffer overflow in iDRAC8 and iDRAC9 - CVE-2021-36347
Published: August 8, 2022
Vulnerability identifier: #VU66164
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36347
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. An authenticated remote user with high privileges can exploit this vulnerability to control process execution and gain access to the iDRAC operating system.
Affected software
iDRAC8
iDRAC9
Dell EMC VxRail Appliance
PowerScale OneFS
Integrated System for Microsoft Azure Stack Hub
iDRAC9
Dell EMC VxRail Appliance
PowerScale OneFS
Integrated System for Microsoft Azure Stack Hub
How to mitigate CVE-2021-36347
Install updates from vendor's website.
iDRAC8 - update to 2.82.82.82
iDRAC9 - update to 5.00.10.20
Dell EMC VxRail Appliance - update to 7.0.350
PowerScale OneFS - update to 11.7
Integrated System for Microsoft Azure Stack Hub - update to 2207
iDRAC9 - update to 5.00.10.20
Dell EMC VxRail Appliance - update to 7.0.350
PowerScale OneFS - update to 11.7
Integrated System for Microsoft Azure Stack Hub - update to 2207