Database/Firmware, BMC & network fabric
Dell iDRAC7/8: Stack buffer overflow in the iDRAC web server — unauthenticated RCE on the BMC
CVSS 9.8CVE-2019-3705Firmware, BMC & network fabriccurated
Impact
Stack buffer overflow in the iDRAC web server — unauthenticated RCE on the BMC
Who can reach it
Network, unauthenticated
What to do
iDRAC7/8 are EOL on many fleets; remediation may require a chassis refresh rather than a patch
References
Related entries
- Dell iDRAC7/8: CGI injection giving unauthenticated remote code execution as root on the BMCCVE-2018-1207 · Dell iDRAC7/8Critical
- Dell iDRAC9: Authentication bypass in the iDRAC9 web interface — full out-of-band control of the serverCVE-2019-3706 · Dell iDRAC9Critical
- Dell iDRAC9: Authentication bypass via the WS-MAN interfaceCVE-2019-3707 · Dell iDRAC9Critical
- ASPEED AST2400 / AST2500 BMC SoC: Arbitrary read/write of the BMC's entire physical address space **from the host CPU**CVE-2019-6260 · ASPEED AST2400 / AST2500 BMC SoCCritical
- NVIDIA DGX BMC (AMI firmware): Hard-coded credentials in the DGX BMC firmwareCVE-2020-11483 · NVIDIA DGX BMC (AMI firmware)Critical
- NVIDIA DGX BMC (AMI firmware): File upload into the BMC that gets automatically processed, yielding remote codeCVE-2020-11486 · NVIDIA DGX BMC (AMI firmware)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.