🔙 목록으로 돌아가기

CVE-2018-1207: Dell iDRAC7/8 Devices - Remote Code Injection

TitleDell iDRAC7/8 Devices - Remote Code Injection
Authordwisiswant0
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected device.
RemediationApply the latest firmware updates provided by Dell to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.9379
CVE IDCVE-2018-1207
CWE IDCWE-94
Tags cve2018 cve dell injection rce vkev vuln

🔍 Vulnerability Description

Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.

🌐 HTTP Request

GET /cgi-bin/login?LD_DEBUG=files HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:140.0.) Gecko/20100101 Firefox/140.0.
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-1207.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-1207.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A