HomeSecurityDell fixes critical vulnerability identified in iDRAC controller!

Dell fixes critical vulnerability identified in iDRAC controller!

A vulnerability has been recently identified in the Dell Embedded Remote Access Controller (iDRAC), which could allow hackers to gain complete control over server operations . The controller is designed to securely manage local and remote servers to help IT administrators deploy, update, and monitor Dell EMC PowerEdge servers.


The Path Traversal vulnerability CVE-2020-5366 was discovered by researchers Georgy Kiguradze and Mark Ermolov of Positive Technologies and has been rated with a score of 7.1 out of 10, which demonstrates the high degree of risk it entails.

DELL iDRAC

Hackers can exploit this vulnerability and turn the product on or off, or change cooling or power settings. Such actions may sound relatively innocuous, but they could potentially have a significant impact on the profits of businesses already grappling with the economic impact of the global COVID-19 pandemic

A Positive Technologies spokesperson said that if important services are running on these servers, this vulnerability could make them temporarily unavailable and even lead to significant losses for businesses.

Kiguradze said that if attackers obtain a privileged user's backup, they could exploit the vulnerability to block or disrupt the server's operation. He also explained that the iDRAC controller is used to manage core servers, effectively acting as a separate computer within the server itself.

vulnerability-hackers

iDRAC runs Linux and has a full system . The vulnerability makes it possible to read any file in the controller's operating system and, in some cases, interfere with the controller's operation.

Additionally, researchers found that the vulnerability affects Dell EMC iDRAC9 with versions prior to 4.20.20.20, and can be exploited internally or externally. Specifically, Kiguradze noted that an attack could be carried out externally – if an attacker has credentials, perhaps by brute-forcing (although this is highly unlikely given the product’s brute-forcing protection) or internally, such as through a junior admin account with limited access to the server.

iDRAC is offered as an option for almost all current Dell servers. After the vulnerability, Dell released updated firmware, urging users to install it as soon as possible. It also recommends that users not connect iDRAC directly to the Internet, but place it on a separate management network.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS