Vulnerability Description
Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Idrac6 Firmware | <= 1.95 |
| Dell | Idrac6 Monolithic | - |
| Dell | Idrac7 Firmware | <= 1.40.40 |
| Dell | Idrac7 | - |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/920038US Government Resource
- http://www.kb.cert.org/vuls/id/BLUU-997QVWUS Government Resource
- http://www.kb.cert.org/vuls/id/920038US Government Resource
- http://www.kb.cert.org/vuls/id/BLUU-997QVWUS Government Resource
FAQ
What is CVE-2013-3589?
CVE-2013-3589 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46....
How severe is CVE-2013-3589?
CVE-2013-3589 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3589?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Idrac6 Firmware, Dell Idrac6 Monolithic, Dell Idrac7 Firmware, Dell Idrac7.