Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.
2021-08-03T16:15:08.213
2024-11-21T05:48:38.763
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dell | emc_idrac8_firmware | < 2.80.80.80 | Yes |
Operating System | dell | emc_idrac9_firmware | < 5.00.00.00 | Yes |