VYPR
Unrated severityNVD Advisory· Published Apr 26, 2019· Updated Sep 17, 2024

Web Interface Authentication Bypass Vulnerability

CVE-2019-3706

Description

Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell EMC iDRAC9 web interface authentication bypass allows remote attackers to bypass authentication and gain system access via specially crafted data.

Vulnerability

Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22, and 3.21.25.22 contain an authentication bypass vulnerability in the web interface. [1] A remote attacker can send specially crafted data to the iDRAC web interface to bypass authentication and gain access to the system. [1]

Exploitation

An unauthenticated remote attacker with network access to the iDRAC web interface can exploit this vulnerability by sending specially crafted input data to the affected system. No prior authentication or user interaction is required; the attack complexity is low according to the CVSSv3 vector (AC:L). [1]

Impact

Successful exploitation allows a remote attacker to bypass authentication and gain access to the iDRAC9 system. The CVSSv3 Base Score is 8.6 (High) with impacts to confidentiality (low), integrity (low), and availability (high). [1] The attacker can potentially compromise the management interface, leading to full system compromise of the managed server.

Mitigation

Dell Technologies released firmware updates to address this vulnerability. Affected users should upgrade to iDRAC9 version 3.24.24.24, 3.21.26.22, 3.22.22.22, or 3.21.25.22, or later. [1] No known workarounds are documented; updating to a fixed version is the recommended mitigation. This CVE is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Dell/iDRAC9llm-fuzzy
    Range: prior to 3.24.24.24, 3.21.26.22, 3.22.22.22, 3.21.25.22
  • Dell/Idrac7cpe-rescue
    Range: 3.24.24.24

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.