Database/Firmware, BMC & network fabric
Dell iDRAC9 (Redfish): Redfish interface permission-check flaw enabling privilege escalation to admin
CVSS 8.8CVE-2018-15774Firmware, BMC & network fabriccurated
Impact
Redfish interface permission-check flaw enabling privilege escalation to admin
Who can reach it
Network / Redfish, authenticated low-privilege
What to do
iDRAC firmware update; illustrates that Redfish RBAC bugs are as common as the IPMI ones they replaced
References
Related entries
- Intel AMT (HTTP handler) in Intel CSME firmware: A buffer overflow in AMT's HTTP handler allows arbitrary codeCVE-2018-3628 · Intel AMT (HTTP handler) in Intel CSME firmwareHigh
- Brocade Fabric OS Webtools (firmware update section): A remote authenticated attacker can abuse the WebtoolsCVE-2018-6442 · Brocade Fabric OS Webtools (firmware update section)High
- Eaton UPS 9PX 8000 SP administration panel: CSRF on the change-password function plus reflected XSS: an attacker forcesCVE-2018-9281 · Eaton UPS 9PX 8000 SP administration panelHigh
- Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710): Buffer overflow in the adapter firmware of Intel'sCVE-2019-0140 · Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710)High
- Intel CSME / TXE: A heap overflow in a CSME subsystem reachable by an unauthenticated attacker for privilege escalationCVE-2019-0169 · Intel CSME / TXEHigh
- Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06: The researcher's own descriptionCVE-2019-19642 · Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.