5
CVSSv2

CVE-2018-1243

Published: 02/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Dell EMC iDRAC6, versions before 2.91, iDRAC7/iDRAC8, versions before 2.60.60.60 and iDRAC9, versions before 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit numeric-only session ID values, which makes it easier for remote malicious users to perform bruteforce session guessing attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dell idrac6 firmware

dell idrac9 firmware

dell idrac8 firmware

dell idrac7 firmware