← back
CVE-2014-8272

CVE-2014-8272

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 21%
from disclosure to weapon25 days
Published on NVDDec 19
1st PoC+25d
exploitation probability
21%top 3% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.