CVE-2021-21543
low-risk
Published 2021-04-30
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain multiple stored cross-site scripting vulnerabilities. A remote authenticated malicious user with high privileges could potentially exploit these vulnerabilities to store malicious HTML or JavaScript code through multiple affected parameters. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
Do I need to act?
-
0.41% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.8/10
Medium
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (2)
Vendor Advisory
https://www.dell.com/support/kbdoc/000185293
Vendor Advisory
https://www.dell.com/support/kbdoc/000185293
26
/ 100
low-risk
Severity
19/34 · Moderate
Exploitability
2/34 · Minimal
Exposure
5/34 · Minimal