High severity8.8NVD Advisory· Published Jul 2, 2018· Updated Jun 17, 2026
CVE-2018-1212
CVE-2018-1212
Description
The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected iDRAC system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:dell:idrac6_modular:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dell:idrac6_modular:*:*:*:*:*:*:*:*
- (no CPE)range: unspecified
cpe:2.3:a:dell:idrac6_monolithic:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dell:idrac6_monolithic:*:*:*:*:*:*:*:*range: <2.91
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1- en.community.dell.com/techcenter/extras/m/white_papers/20487494nvdVendor Advisory
News mentions
0No linked articles in our index yet.