Database/Firmware, BMC & network fabric
Dell iDRAC9 (web interface, local file inclusion): A path-traversal / local-file-inclusion flaw lets a low-privilege
Impact
A path-traversal / local-file-inclusion flaw lets a low-privilege iDRAC user read files outside the intended directory on the BMC. The value to an attacker is escalation material - configuration, credentials and session data that upgrade a read-only monitoring account into real control of the service processor. This is the classic privilege-ladder rung: the account you handed to a monitoring agent becomes the account that owns the node's out-of-band plane.
Who can reach it
An authenticated low-privilege iDRAC operator or read-only account reaching the iDRAC web interface over the management VLAN. No host access needed.
What to do
Flash iDRAC9 to 4.20.20.20 or later - out-of-band, per-node, no host reboot, no drain. There is no clean config-only mitigation for this one beyond tightening who holds iDRAC accounts at all, so treat it as a firmware campaign. Worth pairing with an audit of low-privilege iDRAC service accounts, which are usually shared and rarely rotated.
References
Related entries
- Dell iDRAC9: TOCTOU race during simultaneous web-interface access — state corruption on the BMCCVE-2021-21539 · Dell iDRAC9High
- AMD SEV-ES firmware - TMR placement in MMIO space: SEV-ES firmware does not verify that the Trusted Memory Region isCVE-2021-26332 · AMD SEV-ES firmware - TMR placement in MMIO spaceHigh
- AMD Secure Processor firmware - BIOS mailbox command bounds checking: Insufficient bounds checking while the ASPCVE-2021-26402 · AMD Secure Processor firmware - BIOS mailbox command bounds checkingHigh
- Arista EOS (service ACLs): Service ACL bypass for OpenConfig gNOI and RESTCONFCVE-2021-28507 · Arista EOS (service ACLs)High
- Dell Enterprise SONiC OS (information disclosure): An authenticated user can extract sensitive informationCVE-2021-36309 · Dell Enterprise SONiC OS (information disclosure)High
- Linux kernel (drivers/infiniband/sw/siw): A tenant gets an out-of-bounds kernel array read using values it controls.CVE-2022-50736 · Linux kernel (drivers/infiniband/sw/siw)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.