Database/Firmware, BMC & network fabric
Dell iDRAC7 / iDRAC8 / iDRAC9 (SNMP agent): Command injection in the iDRAC SNMP agent gives an attacker who already
Impact
Command injection in the iDRAC SNMP agent gives an attacker who already holds an iDRAC account with configuration rights arbitrary command execution as root on the BMC itself. That is the full BMC prize: out-of-band power control, Virtual Media boot, KVM, and an implant that lives on the service processor and survives every host reimage and OS reinstall. The privilege jump matters - it converts a routine monitoring or configuration credential into persistent control of the node beneath the hypervisor.
Who can reach it
An authenticated iDRAC account holding the Configure iDRAC privilege - the kind of account handed to monitoring tooling, an integrator, or a datacenter-remote-hands team, not a full administrator. Reachability is the management VLAN.
What to do
Flash to iDRAC7/8 2.60.60.60 or iDRAC9 3.21.21.21 or later - out-of-band, per-node, no host reboot and no job drain. Config-only mitigations that reduce blast radius immediately: disable the iDRAC SNMP agent where you are not actually scraping it, and audit which service accounts hold Configure iDRAC rather than read-only. Original Dell TechCenter advisory URL is dead; NVD carries the version data.
References
Related entries
- Dell iDRAC9 (Redfish): Redfish interface permission-check flaw enabling privilege escalation to adminCVE-2018-15774 · Dell iDRAC9 (Redfish)High
- Intel AMT (HTTP handler) in Intel CSME firmware: A buffer overflow in AMT's HTTP handler allows arbitrary codeCVE-2018-3628 · Intel AMT (HTTP handler) in Intel CSME firmwareHigh
- Brocade Fabric OS Webtools (firmware update section): A remote authenticated attacker can abuse the WebtoolsCVE-2018-6442 · Brocade Fabric OS Webtools (firmware update section)High
- Eaton UPS 9PX 8000 SP administration panel: CSRF on the change-password function plus reflected XSS: an attacker forcesCVE-2018-9281 · Eaton UPS 9PX 8000 SP administration panelHigh
- Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710): Buffer overflow in the adapter firmware of Intel'sCVE-2019-0140 · Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710)High
- Intel CSME / TXE: A heap overflow in a CSME subsystem reachable by an unauthenticated attacker for privilege escalationCVE-2019-0169 · Intel CSME / TXEHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.