Vulnerability Description
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to any user.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Idrac9 Firmware | < 4.40.00.00 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/000185293Vendor Advisory
- https://www.dell.com/support/kbdoc/000185293Vendor Advisory
FAQ
What is CVE-2021-21544?
CVE-2021-21544 is a vulnerability with a CVSS score of 2.7 (LOW). Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability t...
How severe is CVE-2021-21544?
CVE-2021-21544 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21544?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Idrac9 Firmware.