CVE-2018-15776

Published: Dic 13, 2018 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2018-7639 Aliases: GSD-2018-15776
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,4
Attack Vector: physical
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
MEDIUM 4,6
Access Vector: local
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: partial
Availability: partial

Description

AI Translation Available

Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to get access to the u-boot shell.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0072
Percentile
0,7th
Updated

EPSS Score Trend (Last 90 Days)

Operating System

Idrac7 Firmware by Dell

Version Range Affected
To 2.61.60.60 (exclusive)
cpe:2.3:o:dell:idrac7_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Idrac8 Firmware by Dell

Version Range Affected
To 2.61.60.60 (exclusive)
cpe:2.3:o:dell:idrac8_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.dell.com/support/article/us/en/19/sln315190/dell-emc-idrac-multiple…
http://www.securityfocus.com/bid/106233
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/106233
https://www.dell.com/support/article/us/en/19/sln315190/dell-emc-idrac-multiple…
http://www.securityfocus.com/bid/106233
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/106233