CVE-2021-36348
Description
iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell iDRAC9 before 5.00.20.00 has an input injection flaw; a low-privileged authenticated remote attacker can trigger info disclosure or DoS via crafted input.
Vulnerability
Dell EMC iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. The flaw resides in the iDRAC9 web interface or management subsystem that processes user-supplied data. A remote authenticated attacker with low privileges can exploit this by sending specially crafted input data to the iDRAC service [1].
Exploitation
An attacker must be authenticated to the iDRAC9 web interface or management API. The attack is performed over the network, requires low privileges (i.e., a standard user account), and does not require user interaction beyond the initial authentication. By supplying maliciously crafted input data to a vulnerable input field or parameter, the attacker can inject content that the iDRAC processes unsafely [1].
Impact
Successful exploitation can lead to information disclosure (confidentiality breach) or denial of service (availability impact). The CVSS vector indicates a high confidentiality impact and low availability impact, with no integrity impact. The attacker gains access to sensitive data or causes the service to become unavailable, but does not achieve code execution or privilege escalation [1].
Mitigation
Dell EMC released a fixed version 5.00.20.00 for iDRAC9 to remediate this vulnerability. Users should upgrade to this version or later. Dell's security advisory DSA-2021-259 provides the update details [1]. No workarounds have been published; the only mitigation is applying the firmware update.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/000194038mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.