Dell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.
2023-01-18T12:15:10.510
2024-11-21T07:09:33.580
Modified
CVSSv3.1: 2.7 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | dell | idrac8_firmware | < 2.84.84.84 | Yes |
| Hardware | dell | idrac8 | - | No |