Dell iDRAC Products Multiple Vulnerabilities (December 2018)

high Nessus Plugin ID 119833

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The remote host is running iDRAC7 or iDRAC8 with a firmware version prior to 2.61.60.60, or iDRAC9 with a firmware version prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 or 3.23.23.23 and is therefore affected by the following vulnerabilities:

- An elevation of privilege vulnerability exists in Redfish interface. An authenticated, attacker can exploit, via a permissions check flaw, to gain elevated privileges.
(CVE-2018-15774)

- A flaw exists in iDRAC7 / iDRAC8 due to improper handling of an error. A unauthenticated, remote attacker can exploit this to gain access to a u-boot shell. (CVE-2018-15776)

Solution

Update the remote host to iDRAC7/iDRAC8 firmware 2.61.60.60, or iDRAC9 firmware 3.20.21.20, 3.21.24.22, 3.21.26.22, 3.23.23.23 or higher.

See Also

http://www.nessus.org/u?751fcfbd

Plugin Details

Severity: High

ID: 119833

File Name: drac_2018_12_13.nasl

Version: 1.6

Type: remote

Family: CGI abuses

Published: 12/21/2018

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2018-15774

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/h:dell:remote_access_card, cpe:/h:dell:idrac7, cpe:/h:dell:idrac8, cpe:/h:dell:idrac9

Required KB Items: installed_sw/iDRAC

Exploit Ease: No known exploits are available

Patch Publication Date: 12/13/2018

Vulnerability Publication Date: 12/13/2018

Reference Information

CVE: CVE-2018-15774, CVE-2018-15776

BID: 106233

IAVA: 2018-A-0412-S