Database/Firmware, BMC & network fabric
Dell iDRAC9: Stack-based buffer overflow via crafted remote input — pre-auth code execution on the BMC
CVSS 9.8CVE-2020-5344Firmware, BMC & network fabriccurated
Impact
Stack-based buffer overflow via crafted remote input — pre-auth code execution on the BMC
Who can reach it
Network, unauthenticated
What to do
iDRAC firmware update; requires a rolling out-of-band update campaign across the fleet
References
Related entries
- Dell iDRAC9: Stack overflow overwriting iDRAC configuration via oversized payloadsCVE-2021-21540 · Dell iDRAC9High
- Dell iDRAC9: TOCTOU race during simultaneous web-interface access — state corruption on the BMCCVE-2021-21539 · Dell iDRAC9High
- Dell iDRAC9: Authentication bypass in the iDRAC9 web interface — full out-of-band control of the serverCVE-2019-3706 · Dell iDRAC9Critical
- Dell iDRAC9: Authentication bypass via the WS-MAN interfaceCVE-2019-3707 · Dell iDRAC9Critical
- APC Easy UPS On-Line Software (SFAPV9601) FileUploadServlet: Path traversal in a file upload servlet allows writingCVE-2020-7521 · APC Easy UPS On-Line Software (SFAPV9601) FileUploadServletCritical
- Arista EOS (eAPI certificate auth): Certificate-based eAPI authentication skips credential re-evaluationCVE-2021-28503 · Arista EOS (eAPI certificate auth)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.