CVE-2020-5344
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.
Affected (3)
Products: Dell: Idrac7 Firmware, Idrac8 Firmware, Idrac9 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.65.65.65 |
| Running on/with | Platform Versions |
|---|---|
Dell Idrac7 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.70.70.70 |
| Running on/with | Platform Versions |
|---|---|
Dell Idrac8 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.00.00.00 |
| Running on/with | Platform Versions |
|---|---|
Dell Idrac9 | All versions |
Related CWEs
CWE-121
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (2)
Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.