CVE-2021-21543
Last modified
CVE-2021-21543 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Dell EMC iDRAC9 versions prior to 4.40.00.00 contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges could potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected parameters. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges could potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected parameters. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Idrac9 Firmware | < 4.40.00.00 |
References
- https://www.dell.com/support/kbdoc/000185293Vendor Advisory
- https://www.dell.com/support/kbdoc/000185293Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-21543?
How severe is CVE-2021-21543?
How do I fix CVE-2021-21543?
Are you affected by CVE-2021-21543?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
