Database/Firmware, BMC & network fabric
Dell iDRAC9: Stack overflow overwriting iDRAC configuration via oversized payloads
CVSS 8.1CVE-2021-21540Firmware, BMC & network fabriccurated
Impact
Stack overflow overwriting iDRAC configuration via oversized payloads
Who can reach it
Network, authenticated
What to do
iDRAC firmware update
References
Related entries
- Dell iDRAC9: TOCTOU race during simultaneous web-interface access — state corruption on the BMCCVE-2021-21539 · Dell iDRAC9High
- Dell iDRAC9: Authentication bypass in the iDRAC9 web interface — full out-of-band control of the serverCVE-2019-3706 · Dell iDRAC9Critical
- Dell iDRAC9: Authentication bypass via the WS-MAN interfaceCVE-2019-3707 · Dell iDRAC9Critical
- Dell iDRAC9: Stack-based buffer overflow via crafted remote input — pre-auth code execution on the BMCCVE-2020-5344 · Dell iDRAC9Critical
- GRUB2 (net/ip IPv4 reassembly): Integer underflow in grub_net_recv_ip4_packets from a crafted IP packetCVE-2022-28733 · GRUB2 (net/ip IPv4 reassembly)High
- ATEN PE8108 switched PDU: A restricted (non-admin) user account on the PDU's web interface can control outletsCVE-2023-25409 · ATEN PE8108 switched PDUHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.