CVE-2020-26198
Description
Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell EMC iDRAC9 prior to 4.32.10.00 and 4.40.00.00 contain a reflected XSS vulnerability that allows arbitrary HTML/JavaScript execution via a crafted link.
Vulnerability
Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting (XSS) vulnerability in the iDRAC9 web application. This flaw allows an attacker to inject malicious HTML or JavaScript into a page by crafting a specially formed URL. No special configuration is required beyond the affected software versions. [1]
Exploitation
A remote attacker can exploit this vulnerability by convincing a victim to click a specially crafted link, which causes the injected script to be reflected and executed in the victim's browser. The attacker does not need prior authentication, but the victim must interact with the crafted link (user interaction is required). The attack vector is network-based (AV:N), and no privileges are needed (PR:N). [1]
Impact
Successful exploitation results in limited confidentiality and integrity impact (CVSSv3 6.1 – C:L, I:L). The attacker can execute malicious scripts in the victim's browser within the context of the iDRAC9 web session, potentially performing actions on behalf of the victim or stealing session cookies. The scope is changed because the vulnerable application and the malicious content operate in different contexts. [1]
Mitigation
Dell Technologies has released fixed firmware versions: 4.32.10.00 and 4.40.00.00 for iDRAC9. These are available from the Dell Support site. Customers are advised to upgrade as soon as possible. The iDRAC should be isolated on a separate management network as a best practice to reduce exposure. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.