CVE-2013-3589

Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
dellidrac6_firmware
𝑥
≤ 1.95
dellidrac6_firmware
1.0
dellidrac6_firmware
1.1
dellidrac6_firmware
1.2
dellidrac6_firmware
1.3
dellidrac6_firmware
1.5
dellidrac6_firmware
1.6
dellidrac6_firmware
1.8
dellidrac6_monolithic
-
dellidrac7_firmware
𝑥
≤ 1.40.40
dellidrac7_firmware
1.00.00
dellidrac7_firmware
1.06.06
dellidrac7_firmware
1.10.10
dellidrac7_firmware
1.20.20
dellidrac7_firmware
1.23.23
dellidrac7_firmware
1.37.35
dellidrac7
-
𝑥
= Vulnerable software versions