CVE-2018-1249

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/07/2018
Last modified:
09/10/2019

Description

Dell EMC iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for certain URLs. A man-in-the-middle attacker could use this vulnerability to strip the SSL/TLS protection from a connection between a client and a server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:idrac9_firmware:*:*:*:*:*:*:*:* 3.21.21.21 (excluding)