Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.
2023-01-18T12:15:10.427
2024-11-21T07:09:33.443
Modified
CVSSv3.1: 2.7 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dell | idrac9_firmware | < 6.00.30.00 | Yes |
Hardware | dell | idrac9 | - | No |