CVE-2018-1207

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
23/03/2018
Last modified:
24/08/2020

Description

Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:emc_idrac7:*:*:*:*:*:*:*:* 2.52.52.52 (excluding)
cpe:2.3:a:dell:emc_idrac8:*:*:*:*:*:*:*:* 2.52.52.52 (excluding)