Vulnerability Details CVE-2021-36348
iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.0%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 5.5
Products affected by CVE-2021-36348
-
cpe:2.3:h:dell:integrated_dell_remote_access_controller_9:-
-
cpe:2.3:o:dell:integrated_dell_remote_access_controller_9_firmware:-