Dell EMC iDRAC7和iDRAC8都是美国戴尔(Dell)公司的包含硬件和软件的系统管理解决方案。该方案为Dell PowerEdge系统提供远程管理、崩溃系统恢复和电源控制等功能。 Dell EMC iDRAC7和iDRAC8 2.52.52.52之前版本中存在安全漏洞。远程攻击者可借助CGI变量利用该漏洞执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploit iDRAC 7 & 8 firmware < 2.52.52.52 | https://github.com/mgargiullo/cve-2018-1207 | POC Details |
| 2 | A proof of concept for CVE-2018-1207. | https://github.com/un4gi/CVE-2018-1207 | POC Details |
| 3 | A workflow to identify Dell iDRAC instances and run all related nuclei templates. | https://github.com/projectdiscovery/nuclei-templates/blob/main/workflows/dell-idrac-workflow.yaml | POC Details |
| 4 | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-1207.yaml | POC Details |
| 5 | Reverse Shell CVE for iDRAC 7 & 8 with firmware 2.52.52.52 and below. | https://github.com/SYNKTeam/CVE-2018-1207 | POC Details |
| 6 | Reverse Shell CVE for iDRAC 7 & 8 with firmware 2.52.52.52 and below. | https://github.com/hironull/CVE-2018-1207-better | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-8964 | libming 安全漏洞 | |
| CVE-2018-1000140 | rsyslog librelp 缓冲区错误漏洞 | |
| CVE-2017-17736 | Kentico 安全漏洞 | |
| CVE-2018-8949 | MISP 安全漏洞 | |
| CVE-2018-8948 | MISP 跨站脚本漏洞 | |
| CVE-2018-1000136 | GitHub Electron Webviews 安全漏洞 | |
| CVE-2017-18247 | Libav 安全漏洞 | |
| CVE-2017-18246 | Libav 安全漏洞 | |
| CVE-2017-18245 | Libav 安全漏洞 | |
| CVE-2018-1000137 | Scilico I, Librarian 跨站请求伪造漏洞 | |
| CVE-2018-8963 | libming 安全漏洞 | |
| CVE-2018-8962 | libming 安全漏洞 | |
| CVE-2018-8961 | libming 安全漏洞 | |
| CVE-2018-8960 | ImageMagick 缓冲区错误漏洞 | |
| CVE-2018-8957 | CoverCMS 跨站脚本漏洞 | |
| CVE-2018-1000141 | Scilico I, Librarian 访问控制错误漏洞 | |
| CVE-2018-1000139 | Scilico I, Librarian 跨站脚本漏洞 | |
| CVE-2018-1000138 | Scilico I, Librarian 安全漏洞 |
No comments yet