Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit numeric-only session ID values, which makes it easier for remote attackers to perform bruteforce session guessing attacks.
2018-07-02T17:29:00.347
2024-11-21T03:59:27.130
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dell | idrac6_firmware | < 2.91 | Yes |
Operating System | dell | idrac7_firmware | < 2.60.60.60 | Yes |
Operating System | dell | idrac8_firmware | < 2.60.60.60 | Yes |
Operating System | dell | idrac9_firmware | < 3.21.21.21 | Yes |