MEDIUM · 4.3

CVE-2013-3589

Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46....

Vulnerability Description

Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
DellIdrac6 Firmware<= 1.95
DellIdrac6 Monolithic-
DellIdrac7 Firmware<= 1.40.40
DellIdrac7-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-3589?

CVE-2013-3589 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46....

How severe is CVE-2013-3589?

CVE-2013-3589 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-3589?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Idrac6 Firmware, Dell Idrac6 Monolithic, Dell Idrac7 Firmware, Dell Idrac7.