Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.
2023-01-18T12:15:10.427
2024-11-21T07:09:33.443
Modified
CVSSv3.1: 2.7 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | dell | idrac9_firmware | < 6.00.30.00 | Yes |
| Hardware | dell | idrac9 | - | No |