VYPR
Unrated severityNVD Advisory· Published Aug 3, 2021· Updated Sep 17, 2024

CVE-2021-21576

CVE-2021-21576

Description

Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell EMC iDRAC9 before 4.40.40.00 has a DOM-based XSS that lets a remote attacker run malicious HTML/JS by tricking a victim into clicking a crafted link.

Vulnerability

CVE-2021-21576 is a DOM-based cross-site scripting (XSS) vulnerability in the Dell EMC iDRAC9 web interface. All versions prior to firmware 4.40.40.00 are affected. The flaw resides in the handling of user-controlled input in the browser's DOM, allowing the injection of malicious scripts without proper server-side sanitization. No special configuration is required; the vulnerable code path is reachable through normal user interaction with the management console.

Exploitation

To exploit this vulnerability, an attacker must convince a victim to click a specially crafted link. The attacker does not require authentication or network access beyond the ability to deliver the link (e.g., via email, instant message, or a malicious website). Once the victim follows the link, the malicious HTML or JavaScript executes in the context of the iDRAC9 web interface in the victim's browser.

Impact

Successful exploitation allows the attacker to execute arbitrary HTML or JavaScript in the victim's browser within the iDRAC9 session. This can lead to data theft, session hijacking, defacement, or phishing of additional credentials. The CVSS score is 6.1 (Medium) with the vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating low confidentiality and integrity impact but a changed scope.

Mitigation

Dell has released iDRAC9 firmware version 4.40.40.00 which resolves this vulnerability. All users are advised to update to this version or later. No workaround is provided in the references. The vulnerability is not listed on the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog as of the publication date. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.