Database/Firmware, BMC & network fabric
Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injection: A string injection escapes the
Impact
A string injection escapes the restricted racadm command interface and drops the caller into a real Bash shell on the service processor. Any BMC account - including the low-privilege, read-only kind an operator hands to a customer or an NOC contractor for power-cycling their own node - becomes arbitrary code execution on the management controller. From a shell on the iDRAC an attacker persists across host reinstalls, tampers with the host's firmware update path, and watches or drives the host console. This is the pre-2018 example of why 'we only gave them limited BMC access' is not a boundary: the restricted CLI was the boundary, and it is one quoting bug deep.
Who can reach it
Network, post-auth. Any valid iDRAC credential, at any privilege level, over SSH or the racadm interface.
What to do
Flash iDRAC7/iDRAC8 firmware to 2.40.40.40 or later - an out-of-band update that does not require host downtime, roughly 10-15 minutes per node with a brief loss of management access, so it can be run against live nodes if you accept that window. The policy change worth making alongside it: stop issuing per-tenant or per-vendor BMC accounts at all. Broker power and console operations through your own control plane so tenants never hold a credential on the service processor, which removes this entire class rather than this one instance of it.
References
Related entries
- Cisco NX-OS / FXOS (LLDP parser): A malformed LLDP frame reloads the switch. LLDP is enabled by default on essentiallyCVE-2018-0395 · Cisco NX-OS / FXOS (LLDP parser)High
- Dell iDRAC7 / iDRAC8 / iDRAC9 (SNMP agent): Command injection in the iDRAC SNMP agent gives an attacker who alreadyCVE-2018-1244 · Dell iDRAC7 / iDRAC8 / iDRAC9 (SNMP agent)High
- Dell iDRAC9 (Redfish): Redfish interface permission-check flaw enabling privilege escalation to adminCVE-2018-15774 · Dell iDRAC9 (Redfish)High
- Intel AMT (HTTP handler) in Intel CSME firmware: A buffer overflow in AMT's HTTP handler allows arbitrary codeCVE-2018-3628 · Intel AMT (HTTP handler) in Intel CSME firmwareHigh
- Brocade Fabric OS Webtools (firmware update section): A remote authenticated attacker can abuse the WebtoolsCVE-2018-6442 · Brocade Fabric OS Webtools (firmware update section)High
- Eaton UPS 9PX 8000 SP administration panel: CSRF on the change-password function plus reflected XSS: an attacker forcesCVE-2018-9281 · Eaton UPS 9PX 8000 SP administration panelHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.