Dell EMC iDRAC6 Monolithic和Modular都是美国戴尔(Dell)公司的包含硬件和软件的系统管理解决方案。该方案为Dell PowerEdge系统提供远程管理、崩溃系统恢复和电源控制等功能。 Dell EMC iDRAC6 Monolithic 2.91之前版本和Modular中基于Web的诊断控制台存在命令注入漏洞。攻击者可利用该漏洞在受影响iDRAC系统上以root权限执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dell EMC | iDRAC6 (Monolithic) | unspecified ~ 2.91 | - |
|
| Dell EMC | iDRAC6 (Modular) | unspecified ~ 3.85 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-1243 | iDRAC6/iDRAC7/iDRAC8 - Weak CGI session ID vulnerability | |
| CVE-2018-1244 | iDRAC7/iDRAC8/iDrac9 contains a command injection vulnerability in the SNMP agent. | |
| CVE-2018-1249 | iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to |
No comments yet