Database/Firmware, BMC & network fabric
Dell iDRAC9: Authentication bypass via the WS-MAN interface
CVSS 9.8CVE-2019-3707Firmware, BMC & network fabriccurated
Impact
Authentication bypass via the WS-MAN interface
Who can reach it
Network, unauthenticated
What to do
Same iDRAC firmware update; also disable WS-MAN if unused
References
Related entries
- Dell iDRAC9: Stack-based buffer overflow via crafted remote input — pre-auth code execution on the BMCCVE-2020-5344 · Dell iDRAC9Critical
- Dell iDRAC9: Stack overflow overwriting iDRAC configuration via oversized payloadsCVE-2021-21540 · Dell iDRAC9High
- Dell iDRAC9: TOCTOU race during simultaneous web-interface access — state corruption on the BMCCVE-2021-21539 · Dell iDRAC9High
- Dell iDRAC9: Authentication bypass in the iDRAC9 web interface — full out-of-band control of the serverCVE-2019-3706 · Dell iDRAC9Critical
- ASPEED AST2400 / AST2500 BMC SoC: Arbitrary read/write of the BMC's entire physical address space **from the host CPU**CVE-2019-6260 · ASPEED AST2400 / AST2500 BMC SoCCritical
- NVIDIA DGX BMC (AMI firmware): Hard-coded credentials in the DGX BMC firmwareCVE-2020-11483 · NVIDIA DGX BMC (AMI firmware)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.