Stack-based buffer overflow in iDRAC8 and iDRAC9 - CVE-2021-36347

 

Stack-based buffer overflow in iDRAC8 and iDRAC9 - CVE-2021-36347

Published: August 8, 2022


Vulnerability identifier: #VU66164
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36347
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. An authenticated remote user with high privileges can exploit this vulnerability to control process execution and gain access to the iDRAC operating system.


Affected software

iDRAC8
iDRAC9
Dell EMC VxRail Appliance
PowerScale OneFS
Integrated System for Microsoft Azure Stack Hub

How to mitigate CVE-2021-36347

Install updates from vendor's website.

iDRAC8 - update to 2.82.82.82
iDRAC9 - update to 5.00.10.20
Dell EMC VxRail Appliance - update to 7.0.350
PowerScale OneFS - update to 11.7
Integrated System for Microsoft Azure Stack Hub - update to 2207

External References

Related Security Bulletins