Vulnerability Description
Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as password hashes.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Idrac7 Firmware | < 2.65.65.65 |
| Dell | Idrac8 Firmware | < 2.70.70.70 |
| Dell | Idrac9 Firmware | < 3.36.36.36 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/article/sln319317/dsa-2019-137-idrac-improper-authoVendor Advisory
- https://www.dell.com/support/article/sln319317/dsa-2019-137-idrac-improper-authoVendor Advisory
FAQ
What is CVE-2019-3764?
CVE-2019-3764 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malici...
How severe is CVE-2019-3764?
CVE-2019-3764 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-3764?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Idrac7 Firmware, Dell Idrac8 Firmware, Dell Idrac9 Firmware.