ID

VAR-202107-0499


CVE

CVE-2021-21538


TITLE

DELL Dell EMC iDRAC9 Authorization problem vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202105-761

DESCRIPTION

Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the virtual console. DELL Dell EMC iDRAC9 is a set of system management solutions including hardware and software from Dell (DELL). This solution provides functions such as remote management, crash recovery and power control for Dell PowerEdge systems

Trust: 1.08

sources: NVD: CVE-2021-21538 // VULHUB: VHN-379942 // VULMON: CVE-2021-21538

AFFECTED PRODUCTS

vendor:dellmodel:idrac9scope:ltversion:4.40.10.00

Trust: 1.0

vendor:dellmodel:idrac9scope:gteversion:4.40.00.00

Trust: 1.0

sources: NVD: CVE-2021-21538

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-21538
value: CRITICAL

Trust: 1.0

security_alert@emc.com: CVE-2021-21538
value: CRITICAL

Trust: 1.0

CNNVD: CNNVD-202105-761
value: CRITICAL

Trust: 0.6

VULHUB: VHN-379942
value: HIGH

Trust: 0.1

VULMON: CVE-2021-21538
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2021-21538
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

VULHUB: VHN-379942
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-21538
baseSeverity: CRITICAL
baseScore: 10.0
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 6.0
version: 3.1

Trust: 1.0

security_alert@emc.com: CVE-2021-21538
baseSeverity: CRITICAL
baseScore: 9.6
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: LOW
exploitabilityScore: 2.8
impactScore: 6.0
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-379942 // VULMON: CVE-2021-21538 // CNNVD: CNNVD-202105-761 // NVD: CVE-2021-21538 // NVD: CVE-2021-21538

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

sources: VULHUB: VHN-379942 // NVD: CVE-2021-21538

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202105-761

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202105-761

PATCH

title:Dell iDRAC9 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=150265

Trust: 0.6

sources: CNNVD: CNNVD-202105-761

EXTERNAL IDS

db:NVDid:CVE-2021-21538

Trust: 1.8

db:CNNVDid:CNNVD-202105-761

Trust: 0.7

db:VULHUBid:VHN-379942

Trust: 0.1

db:VULMONid:CVE-2021-21538

Trust: 0.1

sources: VULHUB: VHN-379942 // VULMON: CVE-2021-21538 // CNNVD: CNNVD-202105-761 // NVD: CVE-2021-21538

REFERENCES

url:https://www.dell.com/support/kbdoc/000186420

Trust: 1.8

url:https://vigilance.fr/vulnerability/check-point-quantum-smart-1-privilege-escalation-via-idrac9-35401

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-379942 // VULMON: CVE-2021-21538 // CNNVD: CNNVD-202105-761 // NVD: CVE-2021-21538

SOURCES

db:VULHUBid:VHN-379942
db:VULMONid:CVE-2021-21538
db:CNNVDid:CNNVD-202105-761
db:NVDid:CVE-2021-21538

LAST UPDATE DATE

2024-08-14T15:01:26.402000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-379942date:2021-08-06T00:00:00
db:VULMONid:CVE-2021-21538date:2021-08-06T00:00:00
db:CNNVDid:CNNVD-202105-761date:2021-08-09T00:00:00
db:NVDid:CVE-2021-21538date:2021-08-06T16:31:00.097

SOURCES RELEASE DATE

db:VULHUBid:VHN-379942date:2021-07-29T00:00:00
db:VULMONid:CVE-2021-21538date:2021-07-29T00:00:00
db:CNNVDid:CNNVD-202105-761date:2021-05-12T00:00:00
db:NVDid:CVE-2021-21538date:2021-07-29T16:15:08.693