CVE-2021-36299
23.11.2021, 20:15
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to the affected application.
| Vendor | Product | Version |
|---|---|---|
| dell | emc_idrac9_firmware | 4.40.00.00 ≤ 𝑥 < 4.40.29.00 |
| dell | emc_idrac9_firmware | 5.00.00.00 |
𝑥
= Vulnerable software versions