CVE-2021-21581
Description
Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell iDRAC9 before 5.00.00.00 contains a reflected cross-site scripting vulnerability exploitable via a crafted link.
Vulnerability
Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting (XSS) vulnerability in the web interface. An attacker can inject malicious HTML or JavaScript into a page rendered in the victim's browser. No authentication or special configuration is required to reach the vulnerable code path; the vulnerability is triggered by a crafted URL. [1]
Exploitation
A remote, unauthenticated attacker can exploit this vulnerability by tricking a victim into following a specially crafted link. The victim must be using a browser that can access the iDRAC9 web interface. No prior user interaction with the device is needed beyond clicking the malicious link. [1]
Impact
Successful exploitation allows the attacker to execute arbitrary HTML or JavaScript in the victim's browser within the context of the iDRAC9 session. This can lead to integrity compromise (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N) such as modifying displayed content or performing actions on behalf of an authenticated user. No direct information disclosure or remote code execution on the iDRAC itself is described. [1]
Mitigation
Dell has addressed the vulnerability in iDRAC9 firmware version 5.00.00.00 and later. Users should update their iDRAC9 firmware to that version or newer via the Dell support portal. No workarounds are provided; the only mitigation is to apply the fixed release. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/000189193mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.