CVE-2021-21510

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
08/03/2021
Last modified:
24/10/2022

Description

Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:idrac8_firmware:*:*:*:*:*:*:*:* 2.75.100.75 (excluding)