Back
CVE-2018-1207
CRITICAL
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.
Published: Mar 23, 2018
Modified: Jun 17, 2026
CWE-94
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| dell | emc_idrac7 | * < 2.52.52.52 |
| dell | emc_idrac8 | * < 2.52.52.52 |
GitHub Security Advisory GHSA-vm2f-3gpj-98m4
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which...
References (6)
- http://en.community.dell.com/techcenter/extras/m/white_papers/20485410 Vendor Advisory
- http://www.securityfocus.com/bid/103694 Third Party Advisory, VDB Entry
- https://twitter.com/nicowaisman/status/977279766792466432 Third Party Advisory
- http://en.community.dell.com/techcenter/extras/m/white_papers/20485410 Vendor Advisory
- http://www.securityfocus.com/bid/103694 Third Party Advisory, VDB Entry
- https://twitter.com/nicowaisman/status/977279766792466432 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
90.33%
Top 0% most likely to be exploited
Threat Score
76.3 / 100
Data Sources
NVD
EPSS
GitHub