ID

VAR-201904-0130


CVE

CVE-2019-3705


TITLE

plural Dell EMC iDRAC Product buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-004144

DESCRIPTION

Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 and 3.23.23.23 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the webserver or execute arbitrary code on the system with privileges of the webserver by sending specially crafted input data to the affected system. plural Dell EMC iDRAC The product contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. RSA Archer GRC Platform is prone to multiple information disclosure vulnerabilities. An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks. Dell EMC iDRAC9 and others are products of Dell (Dell). Dell EMC iDRAC9 is a system management solution that includes hardware and software. Dell EMC iDRAC6 is a system management solution that includes hardware and software. This solution provides functions such as remote management, crash recovery and power control for Dell PowerEdge systems. Dell EMC iDRAC7 is a system management solution that includes hardware and software. A buffer error vulnerability exists in several Dell products. This vulnerability stems from the incorrect verification of data boundaries when the network system or product performs operations on the memory, resulting in incorrect read and write operations to other associated memory locations. Attackers can exploit this vulnerability to cause buffer overflow or heap overflow, etc. Users' session information is logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks. The database connection password may get logged in plain text in the RSA Archer log files. An authenticated malicious local user with access to the log files may obtain the exposed password to use it in further attacks. CVSSv3 Base Score: 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Recommendation: For CVE-2019-3705, the following RSA Archer releases contain a resolution for this vulnerability: * RSA Archer version 6.5 P1 (6.5.0.1) * RSA Archer version 6.5 P2 (6.5.0.2) [6.5 P2 contains the items fixed in 6.5 P1] * RSA Archer version 6.4 SP1 P5 (6.4.1.5) For CVE-2019-3706, the following RSA Archer releases contain a resolution for this vulnerability: * RSA Archer version 6.5 P2 (6.5.0.2) * RSA Archer version 6.4 SP1 P5 (6.4.1.5) RSA recommends all customers upgrade at the earliest opportunity. Severity Rating For an explanation of Severity Ratings, refer to the Security Advisories Severity Rating (https://community.rsa.com/docs/DOC-47147) knowledge base article. RSA recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability. Legal Information Read and use the information in this RSA Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this advisory, contact RSA Technical Support (https://community.rsa.com/docs/DOC-1294). RSA Security LLC and its affiliates, including without limitation, its ultimate parent company, Dell Technologies, distribute RSA Security Advisories in order to bring to the attention of users of the affected RSA products, important security information. RSA recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. RSA disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall RSA, its affiliates or its suppliers, be liable for any damages wha tsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if RSA, its affiliates or its suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply. Dell Product Security Incident Response Team secure@dell.com -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEP5nobPoCj3pTvhAZgSlofD2Yi6cFAlx4N6AACgkQgSlofD2Y i6dXzQ//XHQsdsvdDqGc85jOTtTRZ0VWhxe3g76dAW7u5tmKt8dyHZF4QqaXtc/p qKRdrWl6SK/ajzxhnF7PaMmLLLAYnHBzL56Vo0ZTjcXD/8rMfTh+WX8v/M06TOjG UgJTdtVGKILsBGmuViwVtvpTLsmeVhbhq34dbMscLhrgjwvrTmsCW3Zv+6w4/x5G umlHR8f+asAYs/JKJ3IvFo5i/v1wKoXsFQVXN8RtySzRVKX+Jx3fsqfCnC+cj4cz 6SnaOPQMBRTPzev4vcWGR4HxoQjE6vl3xgKYyi1bAQf6sZnZpVvzmvPi6OZDfV9q jm+32qvMbwjH2L0POwk7djnmaeZ9qRM3cYihHRJhuOaqW4UyVxhy7ZwZIXeYwOX4 lGiyqt6gtGpUjAFgI1qycGOzVu4W1pZhmIAPRk5KYFapr3BEmgWoDwrvjF7QqRq8 wt5J1Us6XWc4D+wqMIo7YZmnvO9Bz73oxBKqvZXNUJSxfQroAQhcG4DJy+TH+nC7 MWMH2EEdhL5ibCog6AMRksMmU08Cw2gIvKnotOgRIPUnirlfn22IpukqV2prBrHH zOoHOLRx865jPqPPHb4Tp+DvGDwtscwiGyI9AaeemutPbUhlibP/vMyQh8wKItCl F+iHsckY/7Mh2/FH3a0vWb57edaT4lPgvt8JwwP4OfE+a7qXpuA= =lmP4 -----END PGP SIGNATURE-----

Trust: 2.16

sources: NVD: CVE-2019-3705 // JVNDB: JVNDB-2019-004144 // BID: 107209 // VULHUB: VHN-155140 // VULMON: CVE-2019-3705 // PACKETSTORM: 151935

AFFECTED PRODUCTS

vendor:dellmodel:idrac6scope:ltversion:2.92

Trust: 1.8

vendor:dellmodel:idrac7scope:ltversion:2.61.60.60

Trust: 1.8

vendor:dellmodel:idrac8scope:ltversion:2.61.60.60

Trust: 1.8

vendor:dellmodel:idrac9scope:ltversion:3.20.21.20

Trust: 1.8

vendor:dellmodel:idrac9scope:ltversion:3.21.24.22

Trust: 0.8

vendor:dellmodel:idrac9scope:ltversion:3.21.26.22

Trust: 0.8

vendor:dellmodel:idrac9scope:ltversion:3.23.23.23

Trust: 0.8

vendor:emcmodel:rsa archer grc platformscope:eqversion:6.5

Trust: 0.3

vendor:emcmodel:rsa archer grc platform p2scope:neversion:6.5

Trust: 0.3

vendor:emcmodel:rsa archer grc platform p1scope:neversion:6.5

Trust: 0.3

vendor:emcmodel:rsa archer grc platform sp1 p5scope:neversion:6.4

Trust: 0.3

sources: BID: 107209 // JVNDB: JVNDB-2019-004144 // NVD: CVE-2019-3705

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-3705
value: CRITICAL

Trust: 1.0

security_alert@emc.com: CVE-2019-3705
value: HIGH

Trust: 1.0

NVD: CVE-2019-3705
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201903-026
value: CRITICAL

Trust: 0.6

VULHUB: VHN-155140
value: HIGH

Trust: 0.1

VULMON: CVE-2019-3705
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-3705
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-155140
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-3705
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

security_alert@emc.com: CVE-2019-3705
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 5.9
version: 3.0

Trust: 1.0

NVD: CVE-2019-3705
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-155140 // VULMON: CVE-2019-3705 // JVNDB: JVNDB-2019-004144 // CNNVD: CNNVD-201903-026 // NVD: CVE-2019-3705 // NVD: CVE-2019-3705

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.1

problemtype:CWE-120

Trust: 1.0

problemtype:CWE-119

Trust: 0.9

sources: VULHUB: VHN-155140 // JVNDB: JVNDB-2019-004144 // NVD: CVE-2019-3705

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201903-026

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201903-026

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-004144

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-155140

PATCH

title:DSA-2019-028url:https://www.dell.com/support/article/jp/ja/jpdhs1/sln316930/dsa-2019-028-dell-emc-idrac-multiple-vulnerabilities?lang=en

Trust: 0.8

title:Dell EMC RSA Archer Repair measures for information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=89720

Trust: 0.6

sources: JVNDB: JVNDB-2019-004144 // CNNVD: CNNVD-201903-026

EXTERNAL IDS

db:NVDid:CVE-2019-3705

Trust: 3.0

db:BIDid:107209

Trust: 1.0

db:PACKETSTORMid:151935

Trust: 0.8

db:JVNDBid:JVNDB-2019-004144

Trust: 0.8

db:CNNVDid:CNNVD-201903-026

Trust: 0.7

db:VULHUBid:VHN-155140

Trust: 0.1

db:VULMONid:CVE-2019-3705

Trust: 0.1

sources: VULHUB: VHN-155140 // VULMON: CVE-2019-3705 // BID: 107209 // JVNDB: JVNDB-2019-004144 // PACKETSTORM: 151935 // CNNVD: CNNVD-201903-026 // NVD: CVE-2019-3705

REFERENCES

url:https://www.dell.com/support/article/us/en/04/sln316930/dsa-2019-028-dell-emc-idrac-multiple-vulnerabilities?lang=en

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-3705

Trust: 1.5

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-3705

Trust: 0.8

url:http://www.securityfocus.com/bid/107209

Trust: 0.7

url:https://packetstormsecurity.com/files/151935/rsa-archer-grc-platform-information-exposure.html

Trust: 0.6

url:https://vigilance.fr/vulnerability/dell-emc-idrac6-buffer-overflow-29660

Trust: 0.6

url:http://www.rsa.com/

Trust: 0.3

url:https://seclists.org/fulldisclosure/2019/mar/4

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/787.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-3706

Trust: 0.1

url:https://community.rsa.com/docs/doc-1294).

Trust: 0.1

url:https://community.rsa.com/docs/doc-47147)

Trust: 0.1

sources: VULHUB: VHN-155140 // VULMON: CVE-2019-3705 // BID: 107209 // JVNDB: JVNDB-2019-004144 // PACKETSTORM: 151935 // CNNVD: CNNVD-201903-026 // NVD: CVE-2019-3705

CREDITS

The vendor reported this issue.,Dell Product Security Incident Response Team

Trust: 0.6

sources: CNNVD: CNNVD-201903-026

SOURCES

db:VULHUBid:VHN-155140
db:VULMONid:CVE-2019-3705
db:BIDid:107209
db:JVNDBid:JVNDB-2019-004144
db:PACKETSTORMid:151935
db:CNNVDid:CNNVD-201903-026
db:NVDid:CVE-2019-3705

LAST UPDATE DATE

2024-11-23T22:21:43.998000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-155140date:2020-10-16T00:00:00
db:VULMONid:CVE-2019-3705date:2020-10-16T00:00:00
db:BIDid:107209date:2019-02-28T00:00:00
db:JVNDBid:JVNDB-2019-004144date:2019-05-28T00:00:00
db:CNNVDid:CNNVD-201903-026date:2020-10-19T00:00:00
db:NVDid:CVE-2019-3705date:2024-11-21T04:42:22.237

SOURCES RELEASE DATE

db:VULHUBid:VHN-155140date:2019-04-26T00:00:00
db:VULMONid:CVE-2019-3705date:2019-04-26T00:00:00
db:BIDid:107209date:2019-02-28T00:00:00
db:JVNDBid:JVNDB-2019-004144date:2019-05-28T00:00:00
db:PACKETSTORMid:151935date:2019-03-03T16:00:16
db:CNNVDid:CNNVD-201903-026date:2019-03-03T00:00:00
db:NVDid:CVE-2019-3705date:2019-04-26T19:29:00.527