Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.
2016-11-29T15:59:00.200
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dell | idrac7_firmware | ≤ 2.30.30.30 | Yes |
Operating System | dell | idrac8_firmware | ≤ 2.30.30.30 | Yes |
Hardware | dell | idrac7 | - | No |
Hardware | dell | idrac8 | - | No |