CVE-2018-1211

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
23/03/2018
Last modified:
19/04/2018

Description

Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI parser which could be used to obtain specific sensitive data without authentication. A remote unauthenticated attacker may be able to read configuration settings from the iDRAC by querying specific URI strings.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:emc_idrac7:*:*:*:*:*:*:*:* 2.52.52.52 (excluding)
cpe:2.3:a:dell:emc_idrac8:*:*:*:*:*:*:*:* 2.52.52.52 (excluding)