Unrated severityNVD Advisory· Published Jul 2, 2018· Updated Sep 16, 2024
iDRAC6/iDRAC7/iDRAC8 - Weak CGI session ID vulnerability
CVE-2018-1243
Description
Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit numeric-only session ID values, which makes it easier for remote attackers to perform bruteforce session guessing attacks.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- en.community.dell.com/techcenter/extras/m/white_papers/20487494mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.