Vulnerability Description
The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected iDRAC system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Idrac6 Modular | All versions |
| Dell | Idrac6 Monolithic | < 2.91 |
Related Weaknesses (CWE)
References
- http://en.community.dell.com/techcenter/extras/m/white_papers/20487494Vendor Advisory
- http://en.community.dell.com/techcenter/extras/m/white_papers/20487494Vendor Advisory
FAQ
What is CVE-2018-1212?
CVE-2018-1212 is a vulnerability with a CVSS score of 8.8 (HIGH). The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC use...
How severe is CVE-2018-1212?
CVE-2018-1212 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1212?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Idrac6 Modular, Dell Idrac6 Monolithic.