mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 01:31:01 +00:00
21 lines
1.0 KiB
Markdown
21 lines
1.0 KiB
Markdown
### [CVE-2018-15774](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15774)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with operator privileges could potentially exploit a permissions check flaw in the Redfish interface to gain administrator access.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/Fohdeesha/idrac-7-8-reverse-engineering
|
|
- https://github.com/chnzzh/Redfish-CVE-lib
|
|
- https://github.com/chnzzh/iDRAC-CVE-lib
|
|
- https://github.com/l4rz/reverse-engineering-dell-idrac-to-get-rid-of-gpu-throttling
|
|
|