CVE-2019-3764

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/11/2019
Last modified:
16/10/2020

Description

Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as password hashes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:idrac7_firmware:*:*:*:*:*:*:*:* 2.65.65.65 (excluding)
cpe:2.3:o:dell:idrac8_firmware:*:*:*:*:*:*:*:* 2.70.70.70 (excluding)
cpe:2.3:o:dell:idrac9_firmware:*:*:*:*:*:*:*:* 3.36.36.36 (excluding)