Vulnerability Description
Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Emc Idrac8 Firmware | < 2.80.80.80 |
| Dell | Emc Idrac9 Firmware | < 5.00.00.00 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/000189193Vendor Advisory
- https://www.dell.com/support/kbdoc/000189193Vendor Advisory
FAQ
What is CVE-2021-21580?
CVE-2021-21580 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized m...
How severe is CVE-2021-21580?
CVE-2021-21580 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21580?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Emc Idrac8 Firmware, Dell Emc Idrac9 Firmware.