CVE-2024-25943

iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker could potentially exploit this vulnerability, leading to arbitrary code execution on the vulnerable application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:idrac9:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:dell:idrac9:*:*:*:*:*:*:*:*

History

03 Feb 2025, 15:24

Type Values Removed Values Added
CPE cpe:2.3:a:dell:idrac9:*:*:*:*:*:*:*:*
First Time Dell
Dell idrac9
CWE NVD-CWE-noinfo
References () https://www.dell.com/support/kbdoc/en-us/000226503/dsa-2024-099-security-update-for-dell-idrac9-ipmi-session-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000226503/dsa-2024-099-security-update-for-dell-idrac9-ipmi-session-vulnerability - Vendor Advisory

Information

Published : 2024-06-29 13:15

Updated : 2025-02-03 15:24


NVD link : CVE-2024-25943

Mitre link : CVE-2024-25943

CVE.ORG link : CVE-2024-25943


JSON object : View

Products Affected

dell

  • idrac9
CWE
CWE-330

Use of Insufficiently Random Values

NVD-CWE-noinfo