Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000183758


DSA-2021-041: Dell iDRAC 8 Security Update for a host header injection vulnerability.

Summary: DSA-2021-041: Dell iDRAC 8 Security Update for a host header injection vulnerability.

Article Content


Impact

Medium

Details

 
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21510 Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability.  A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.   6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
 
 
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21510 Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability.  A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.   6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
 
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

 
Product Affected Version(s) Updated Version(s) CVE Link to Update
iDRAC8 Versions prior to 2.75.100.75 Dell iDRAC8 2.75.100.75 CVE-2021-21510 Customers can download software, including the latest release of iDRAC firmware, from the Dell Support site at https://www.dell.com/support/home/

Customers can find the iDRAC documentation from the Dell EMC Support site at www.dell.com/idracmanuals
 
 

 
Product Affected Version(s) Updated Version(s) CVE Link to Update
iDRAC8 Versions prior to 2.75.100.75 Dell iDRAC8 2.75.100.75 CVE-2021-21510 Customers can download software, including the latest release of iDRAC firmware, from the Dell Support site at https://www.dell.com/support/home/

Customers can find the iDRAC documentation from the Dell EMC Support site at www.dell.com/idracmanuals
 
 

Acknowledgements

CVE-2021-21510: Dell would like to thank Ken Pyle from CYBIR for reporting this vulnerability.

Revision History

 

RevisionDateDescription
1.02021-03-04Initial Release

Related Information


Article Properties


Affected Product
iDRAC8, iDRAC8 with Lifecycle Controller Version 2.12.12.12, iDRAC8 with Lifecycle Controller Version 2.14.14.12, iDRAC8 with Lifecycle Controller Version 2.17.17.13, iDRAC8 with Lifecycle Controller Version 2.18.17.13 , iDRAC8 with Lifecycle Controller Version 2.30.119.30, iDRAC8 with Lifecycle Controller Version 2.35.35.35, iDRAC8 with Lifecycle Controller Version 2.42.110.40, iDRAC8 with Lifecycle Controller Version 2.45.45.40, iDRAC8 with Lifecycle Controller Version 2.55.55.50, iDRAC8 with Lifecycle Controller version 2.70.70.70, iDRAC8 with Lifecycle Controller version 2.75.75.75, iDRAC8 with Lifecycle Controller Version 2.04.02.01, iDRAC8 with Lifecycle Controller Version 2.05.05.05, iDRAC8 with Lifecycle Controller Version 2.23.23.21, iDRAC8 with Lifecycle Controller Version 2.00.00.00, iDRAC8 with Lifecycle Controller Version 2.02.01.01, Product Security Information ...
Last Published Date

23 Nov 2021

Article Type

Dell Security Advisory