Database/Firmware, BMC & network fabric
Dell iDRAC7/8: CGI injection giving unauthenticated remote code execution as root on the BMC
CVSS 9.8CVE-2018-1207Firmware, BMC & network fabriccurated
Impact
CGI injection giving unauthenticated remote code execution as root on the BMC
Who can reach it
Network, unauthenticated
What to do
Firmware update to 2.52.52.52+; nodes still on older iDRAC7/8 firmware are the most common legacy hole in a mixed-vintage GPU fleet
References
Related entries
- Dell iDRAC7/8: Stack buffer overflow in the iDRAC web server — unauthenticated RCE on the BMCCVE-2019-3705 · Dell iDRAC7/8Critical
- Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems): An unprivilegedCVE-2018-12171 · Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems)Critical
- QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 switch modules for IBM BladeCenter: Three undocumentedCVE-2018-18202 · QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 switch modules for IBM BladeCenterCritical
- Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): The card's integrated web serverCVE-2018-7243 · Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS)Critical
- Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): On default settings without SSL enabledCVE-2018-7246 · Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS)Critical
- APC UPS Network Management Card 2 (AOS 6.5.6): When Remote Monitoring is turned on and then off again, the credentialsCVE-2018-7820 · APC UPS Network Management Card 2 (AOS 6.5.6)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.