CVE-2014-8272

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/12/2014
Last modified:
12/04/2025

Description

The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:idrac6_modular:*:*:*:*:*:*:*:* 3.60 (including)
cpe:2.3:a:dell:idrac7:*:*:*:*:*:*:*:* 1.56.55 (including)
cpe:2.3:a:intel:ipmi:1.5:*:*:*:*:*:*:*
cpe:2.3:a:dell:idrac6_monolithic:*:*:*:*:*:*:*:* 1.97 (including)