Time-of-check Time-of-use (TOCTOU) Race Condition in iDRAC9 - CVE-2021-21539
Published: August 9, 2022
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to a Time-of-check Time-of-use (TOCTOU) race condition. A remote unauthenticated attacker can exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.
Affected software
EMC Data Domain
How to mitigate CVE-2021-21539
EMC Data Domain - addressed in versions 6.2.1.60, 7.2.0.70, 7.6.0.7