cve/2024/CVE-2024-25943.md
2024-07-25 21:25:12 +00:00

18 lines
862 B
Markdown

### [CVE-2024-25943](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25943)
![](https://img.shields.io/static/v1?label=Product&message=Integrated%20Dell%20Remote%20Access%20Controller%209&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=N%2FA%3C%207.00.00.172%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-330%3A%20Use%20of%20Insufficiently%20Random%20Values&color=brighgreen)
### Description
iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker could potentially exploit this vulnerability, leading to arbitrary code execution on the vulnerable application.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/chnzzh/iDRAC-CVE-lib