CVE-2021-36347

iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the iDRAC operating system.
References
Link Resource
https://www.dell.com/support/kbdoc/000194038 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:integrated_dell_remote_access_controller_8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:integrated_dell_remote_access_controller_8:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:integrated_dell_remote_access_controller_9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:integrated_dell_remote_access_controller_9:-:*:*:*:*:*:*:*

History

31 Jan 2022, 21:34

Type Values Removed Values Added
CPE cpe:2.3:h:dell:integrated_dell_remote_access_controller_8:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:integrated_dell_remote_access_controller_9:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:integrated_dell_remote_access_controller_8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:integrated_dell_remote_access_controller_9_firmware:*:*:*:*:*:*:*:*
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : 9.0
v3 : 7.2
First Time Dell integrated Dell Remote Access Controller 9
Dell integrated Dell Remote Access Controller 8 Firmware
Dell
Dell integrated Dell Remote Access Controller 9 Firmware
Dell integrated Dell Remote Access Controller 8
References (MISC) https://www.dell.com/support/kbdoc/000194038 - (MISC) https://www.dell.com/support/kbdoc/000194038 - Vendor Advisory

25 Jan 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-25 23:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-36347

Mitre link : CVE-2021-36347

CVE.ORG link : CVE-2021-36347


JSON object : View

Products Affected

dell

  • integrated_dell_remote_access_controller_8
  • integrated_dell_remote_access_controller_9_firmware
  • integrated_dell_remote_access_controller_9
  • integrated_dell_remote_access_controller_8_firmware
CWE
CWE-787

Out-of-bounds Write

CWE-121

Stack-based Buffer Overflow