Input validation error in iDRAC8 - CVE-2022-24423
Published: November 17, 2022
Vulnerability identifier: #VU69406
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24423
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause resource exhaustion in the webserver, resulting in a denial of service condition.
Affected software
iDRAC8
Dell EMC VxRail Appliance
Integrated System for Microsoft Azure Stack Hub
Dell EMC VxRail Appliance
Integrated System for Microsoft Azure Stack Hub
How to mitigate CVE-2022-24423
Install updates from vendor's website.
iDRAC8 - update to 2.83.83.83
Dell EMC VxRail Appliance - update to 4.5.480
Integrated System for Microsoft Azure Stack Hub - update to 2207
Dell EMC VxRail Appliance - update to 4.5.480
Integrated System for Microsoft Azure Stack Hub - update to 2207