CVE-2022-34435

Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.
References
Link Resource
https://www.dell.com/support/kbdoc/000205346 Patch Vendor Advisory
https://www.dell.com/support/kbdoc/000205346 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:idrac9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:idrac9:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:09

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/000205346 - Patch, Vendor Advisory () https://www.dell.com/support/kbdoc/000205346 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 4.9
v2 : unknown
v3 : 2.7
Summary
  • (es) Dell iDRAC9 6.00.02.00 y anteriores contienen una vulnerabilidad de validación de entrada incorrecta en Racadm cuando se establece la configuración de bloqueo del firmware. Un atacante remoto con privilegios elevados podría aprovechar esta vulnerabilidad para evitar la configuración de bloqueo del firmware y realizar una actualización del firmware.

07 Nov 2023, 03:48

Type Values Removed Values Added
Summary Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update. Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update.

Information

Published : 2023-01-18 12:15

Updated : 2024-11-21 07:09


NVD link : CVE-2022-34435

Mitre link : CVE-2022-34435

CVE.ORG link : CVE-2022-34435


JSON object : View

Products Affected

dell

  • idrac9
  • idrac9_firmware
CWE
CWE-20

Improper Input Validation