CVE-2013-3589
Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web…
Does this matter?
Lower severity and a low EPSS score (1.63%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- dell/idrac6 firmware · dell/idrac6 monolithic · dell/idrac7 firmware · dell/idrac7
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/920038US Government Resource
- http://www.kb.cert.org/vuls/id/BLUU-997QVWUS Government Resource
- http://www.kb.cert.org/vuls/id/920038US Government Resource
- http://www.kb.cert.org/vuls/id/BLUU-997QVWUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.