Vulnerability Description
Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Idrac9 Firmware | 3.20.21.20 |
References
- https://www.dell.com/support/article/us/en/04/sln316930/dsa-2019-028-dell-emc-idVendor Advisory
- https://www.dell.com/support/article/us/en/04/sln316930/dsa-2019-028-dell-emc-idVendor Advisory
FAQ
What is CVE-2019-3706?
CVE-2019-3706 is a vulnerability with a CVSS score of 8.6 (HIGH). Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypa...
How severe is CVE-2019-3706?
CVE-2019-3706 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-3706?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Idrac9 Firmware.