Improper Authentication in iDRAC9 - CVE-2022-24422

 

Improper Authentication in iDRAC9 - CVE-2022-24422

Published: August 8, 2022


Vulnerability identifier: #VU66177
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24422
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker can bypass authentication process and gain access to the VNC Console.


Affected software

iDRAC9
Avamar Data Store Gen5A
Dell EMC VxRail Appliance
PowerProtect Data Domain

How to mitigate CVE-2022-24422

Install updates from vendor's website.

iDRAC9 - update to 5.10.10.00
Dell EMC VxRail Appliance - update to 4.5.480
PowerProtect Data Domain - update to 7.9.0.0

External References

Related Security Bulletins