VYPR
Unrated severityNVD Advisory· Published Aug 3, 2021· Updated Sep 16, 2024

CVE-2021-21581

CVE-2021-21581

Description

Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell iDRAC9 before 5.00.00.00 contains a reflected cross-site scripting vulnerability exploitable via a crafted link.

Vulnerability

Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting (XSS) vulnerability in the web interface. An attacker can inject malicious HTML or JavaScript into a page rendered in the victim's browser. No authentication or special configuration is required to reach the vulnerable code path; the vulnerability is triggered by a crafted URL. [1]

Exploitation

A remote, unauthenticated attacker can exploit this vulnerability by tricking a victim into following a specially crafted link. The victim must be using a browser that can access the iDRAC9 web interface. No prior user interaction with the device is needed beyond clicking the malicious link. [1]

Impact

Successful exploitation allows the attacker to execute arbitrary HTML or JavaScript in the victim's browser within the context of the iDRAC9 session. This can lead to integrity compromise (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N) such as modifying displayed content or performing actions on behalf of an authenticated user. No direct information disclosure or remote code execution on the iDRAC itself is described. [1]

Mitigation

Dell has addressed the vulnerability in iDRAC9 firmware version 5.00.00.00 and later. Users should update their iDRAC9 firmware to that version or newer via the Dell support portal. No workarounds are provided; the only mitigation is to apply the fixed release. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.