Database/Firmware, BMC & network fabric
Dell iDRAC9: TOCTOU race during simultaneous web-interface access — state corruption on the BMC
CVSS 7.1CVE-2021-21539Firmware, BMC & network fabriccurated
Impact
TOCTOU race during simultaneous web-interface access — state corruption on the BMC
Who can reach it
Network, authenticated
What to do
iDRAC firmware update
References
Related entries
- Dell iDRAC9: Authentication bypass in the iDRAC9 web interface — full out-of-band control of the serverCVE-2019-3706 · Dell iDRAC9Critical
- Dell iDRAC9: Authentication bypass via the WS-MAN interfaceCVE-2019-3707 · Dell iDRAC9Critical
- Dell iDRAC9: Stack-based buffer overflow via crafted remote input — pre-auth code execution on the BMCCVE-2020-5344 · Dell iDRAC9Critical
- Dell iDRAC9: Stack overflow overwriting iDRAC configuration via oversized payloadsCVE-2021-21540 · Dell iDRAC9High
- AMD SEV-ES firmware - TMR placement in MMIO space: SEV-ES firmware does not verify that the Trusted Memory Region isCVE-2021-26332 · AMD SEV-ES firmware - TMR placement in MMIO spaceHigh
- AMD Secure Processor firmware - BIOS mailbox command bounds checking: Insufficient bounds checking while the ASPCVE-2021-26402 · AMD Secure Processor firmware - BIOS mailbox command bounds checkingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.