Vulnerability Description
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Idrac9 | >= 5.00.00.00, < 5.10.10.00 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000199267/dsa-2022-068-dell-idrac9-secuPatchVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000199267/dsa-2022-068-dell-idrac9-secuPatchVendor Advisory
FAQ
What is CVE-2022-24422?
CVE-2022-24422 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gai...
How severe is CVE-2022-24422?
CVE-2022-24422 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-24422?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Idrac9.