GPU VulnDB

Database/Firmware, BMC & network fabric

Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injection: A string injection escapes the

CVE-2016-5685Firmware, BMC & network fabriccurated

Impact

A string injection escapes the restricted racadm command interface and drops the caller into a real Bash shell on the service processor. Any BMC account - including the low-privilege, read-only kind an operator hands to a customer or an NOC contractor for power-cycling their own node - becomes arbitrary code execution on the management controller. From a shell on the iDRAC an attacker persists across host reinstalls, tampers with the host's firmware update path, and watches or drives the host console. This is the pre-2018 example of why 'we only gave them limited BMC access' is not a boundary: the restricted CLI was the boundary, and it is one quoting bug deep.

Who can reach it

Network, post-auth. Any valid iDRAC credential, at any privilege level, over SSH or the racadm interface.

What to do

Flash iDRAC7/iDRAC8 firmware to 2.40.40.40 or later - an out-of-band update that does not require host downtime, roughly 10-15 minutes per node with a brief loss of management access, so it can be run against live nodes if you accept that window. The policy change worth making alongside it: stop issuing per-tenant or per-vendor BMC accounts at all. Broker power and console operations through your own control plane so tenants never hold a credential on the service processor, which removes this entire class rather than this one instance of it.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.