← back
CVE-2021-36346mediumCWE-287

CVE-2021-36346

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 4.2%
exploitation probability
4.2%top 10% of all CVEs
observed exploitation
nono source reports it
In short

Dell iDRAC 8 versions before 2.82.82.82 have a flaw that allows an attacker without authentication to shut down or make the management web interface unavailable, disrupting remote server management.

Technical detail

An unauthenticated remote attacker can send crafted requests to the iDRAC 8 webserver (pre-authentication vector) to trigger a denial of service condition, rendering the iDRAC management interface inaccessible. This affects versions prior to 2.82.82.82 and impacts server management availability.

Summary generated and translated by AI from the official description.
Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to deny access to the iDRAC webserver.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L